Alerts This Week
Warning Icon 1 684
Alerts This Week
Warning Icon 1 684

Ubuntu 15.10: 2899-1 Critical: LibreOffice Code Execution Risk

Ubuntu Large Esm H500
LibreOffice could be made to crash or run programs as your login if it opened a specially crafted file.
=========================================================================Ubuntu Security Notice USN-2899-1
February 16, 2016

libreoffice vulnerabilities
=========================================================================
A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 15.10
- Ubuntu 14.04 LTS
- Ubuntu 12.04 LTS

Summary:

LibreOffice could be made to crash or run programs as your login if it
opened a specially crafted file.

Software Description:
- libreoffice: Office productivity suite

Details:

It was discovered that LibreOffice incorrectly handled LWP document files.
If a user were tricked into opening a specially crafted LWP document, a
remote attacker could cause LibreOffice to crash, and possibly execute
arbitrary code.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 15.10:
  libreoffice-core                1:5.0.5~rc2-0ubuntu2

Ubuntu 14.04 LTS:
  libreoffice-core                1:4.2.8-0ubuntu4

Ubuntu 12.04 LTS:
  libreoffice-core                1:3.5.7-0ubuntu10

After a standard system update you need to restart LibreOffice to make all
the necessary changes.

References:
  https://ubuntu.com/security/notices/USN-2899-1
  CVE-2016-0794, CVE-2016-0795

Package Information:
  https://launchpad.net/ubuntu/+source/libreoffice/1:5.0.5~rc2-0ubuntu2
  https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu4
  https://launchpad.net/ubuntu/+source/libreoffice/1:3.5.7-0ubuntu10


Ubuntu 15.10: 2899-1 Critical: LibreOffice Code Execution Risk

ubuntu
Calendar Grey February 16, 2016
Dist Ubuntu Esm H88
Opening a specially designed file in LibreOffice may lead to crashes or allow the execution of harmful code. Ensure your system is updated to mitigate this risk.
LibreOffice could be made to crash or run programs as your login if it opened a specially crafted file.

Summary

Update Instructions

The problem can be corrected by updating your system to the following package versions: Ubuntu 15.10: libreoffice-core 1:5.0.5~rc2-0ubuntu2 Ubuntu 14.04 LTS: libreoffice-core 1:4.2.8-0ubuntu4 Ubuntu 12.04 LTS: libreoffice-core 1:3.5.7-0ubuntu10 After a standard system update you need to restart LibreOffice to make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-2899-1

CVE-2016-0794, CVE-2016-0795

Severity
critical
Lowest
Low
Medium
High
Critical

February 16, 2016

Package Information

https://launchpad.net/ubuntu/+source/libreoffice/1:5.0.5~rc2-0ubuntu2 https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu4 https://launchpad.net/ubuntu/+source/libreoffice/1:3.5.7-0ubuntu10

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here