Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 515
Alerts This Week
Warning Icon 1 515

Ubuntu 20.04 LTS: USN-6023-1 Moderate LibreOffice Code Execution Issue

ubuntu
Calendar Grey April 17, 2023
Scroller Ubuntu
Ubuntu Security Notice USN-6022-1 highlights the vulnerability in LibreOffice that could let an attacker execute arbitrary code.
LibreOffice could be made to run arbitrary code if an empty entry to the java class path is configured.

Summary

LibreOffice could be made to run arbitrary code if an empty entry to the

java class path is configured.

Software Description:

- libreoffice: Office productivity suite

Details:

It was discovered that LibreOffice may be configured to add an

empty entry to the Java class path. This may lead to run arbitrary

Java code from the current directory.

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 20.04 LTS:
  libreoffice                     1:6.4.7-0ubuntu0.20.04.7

Ubuntu 18.04 LTS:
  libreoffice                     1:6.0.7-0ubuntu0.18.04.13

In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-6023-1

CVE-2022-38745

April 17, 2023

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.