Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 508
Alerts This Week
Warning Icon 1 508

Ubuntu 15.04 LTS USN-2793-1 Critical: LibreOffice Document Handling Issues

ubuntu
Calendar Grey November 5, 2015
Scroller Ubuntu
Multiple vulnerabilities have been addressed in LibreOffice across different Ubuntu distributions. Ensure your software is updated for enhanced security.
Several security issues were fixed in LibreOffice.

Summary

Several security issues were fixed in LibreOffice.

Software Description:

- libreoffice: Office productivity suite

Details:

Federico Scrinzi discovered that LibreOffice incorrectly handled documents

inserted into Writer or Calc via links. If a user were tricked into opening

a specially crafted document, a remote attacker could possibly obtain the

contents of arbitrary files. (CVE-2015-4551)

It was discovered that LibreOffice incorrectly handled PrinterSetup data

stored in ODF files. If a user were tricked into opening a specially

crafted ODF document, a remote attacker could cause LibreOffice to crash,

and possibly execute arbitrary code. (CVE-2015-5212)

It was discovered that LibreOffice incorrectly handled the number of pieces

in DOC files. If a user were tricked into opening a specially crafted DOC

document, a remote attacker could cause LibreOffice to crash, and possibly

execute arbitrary code. (CVE-2015-5213)

It was discovered that LibreOffice incor...

Read the Full Advisory

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 15.04:
  libreoffice-core                1:4.4.6~rc3-0ubuntu1

Ubuntu 14.04 LTS:
  libreoffice-core                1:4.2.8-0ubuntu3

Ubuntu 12.04 LTS:
  libreoffice-core                1:3.5.7-0ubuntu9

After a standard system update you need to restart LibreOffice to make all
the necessary changes.

References

https://ubuntu.com/security/notices/USN-2793-1

CVE-2015-4551, CVE-2015-5212, CVE-2015-5213, CVE-2015-5214

Severity
critical
Lowest
Low
Medium
High
Critical

November 05, 2015

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.