Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 542
Alerts This Week
Warning Icon 1 542

Ubuntu 14.04 LTS USN-2331-1: Critical LibreOffice Command Injection

ubuntu
Calendar Grey September 2, 2014
Scroller Ubuntu
Ensure you upgrade your LibreOffice software to fix a serious command injection vulnerability that may result in application failures or the unauthorized execution of applications.
LibreOffice Calc could be made to crash or run programs as your login if it opened a specially crafted file.

Summary

LibreOffice Calc could be made to crash or run programs as your login if it

opened a specially crafted file.

Software Description:

- libreoffice: Office productivity suite

Details:

Rohan Durve and James Kettle discovered LibreOffice Calc sometimes allowed

for command injection when opening spreadsheets. If a user were tricked

into opening a crafted Calc spreadsheet, an attacker could exploit this to

run programs as your login.

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 14.04 LTS:
  libreoffice-core                1:4.2.6.3-0ubuntu1

After a standard system update you need to restart LibreOffice to make
all the necessary changes.

References

https://ubuntu.com/security/notices/USN-2331-1

CVE-2014-3524

Severity
critical
Lowest
Low
Medium
High
Critical

=========================================================================Ubuntu Security Notice USN-2331-1

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.