Several security issues were fixed in LibreOffice.. =========================================================================Ubuntu Security Notice USN-5694-1 October 20, 2022 libreoffice vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS Summary: Several security issues were fixed in LibreOffice. Software Description: - libreoffice: Office productivity suite Details: It was discovered that LibreOffice incorrectly handled links using the Office URI Schemes. If a user were tricked into opening a specially crafted document, a remote attacker could use this issue to execute arbitrary scripts. (CVE-2022-3140) Thomas Florian discovered that LibreOffice incorrectly handled crashes when an encrypted document is open. If the document is recovered upon restarting LibreOffice, subsequent saves of the document were unencrypted. This issue only affected Ubuntu 18.04 LTS. (CVE-2020-12801) Jens Müller discovered that LibreOffice incorrectly handled certain documents containing forms. If a user were tricked into opening a specially crafted document, a remote attacker could overwrite arbitrary files when the form was submitted. This issue only affected Ubuntu 18.04 LTS. (CVE-2020-12803) It was discovered that LibreOffice incorrectly validated macro signatures. If a user were tricked into opening a specially crafted document, a remote attacker could possibly use this issue to execute arbitrary macros. This issue only affected Ubuntu 18.04 LTS. (CVE-2022-26305) It was discovered that Libreoffice incorrectly handled encrypting the master key provided by the user for storing passwords for web connections. A local attacker could possibly use this issue to obtain access to passwords stored in the user’s configuration data. This issue only affected Ubuntu 18.04 LTS. (CVE-2022-26306, CVE-2022-26307) Updateinstructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 22.04 LTS: libreoffice 1:7.3.6-0ubuntu0.22.04.2 Ubuntu 20.04 LTS: libreoffice 1:6.4.7-0ubuntu0.20.04.6 Ubuntu 18.04 LTS: libreoffice 1:6.0.7-0ubuntu0.18.04.12 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-5694-1 CVE-2020-12801, CVE-2020-12803, CVE-2022-26305, CVE-2022-26306, CVE-2022-26307, CVE-2022-3140 Package Information: https://launchpad.net/ubuntu/+source/libreoffice/1:7.3.6-0ubuntu0.22.04.2 https://launchpad.net/ubuntu/+source/libreoffice/1:6.4.7-0ubuntu0.20.04.6 . Critical vulnerabilities in LibreOffice can lead to document-related exploits, requiring immediate updates for Ubuntu.. LibreOffice Security, Document Exploits, Ubuntu Security Updates. . Severity: Critical. LinuxSecurity.com Team
Several vulnerabilities were discovered in djvulibre, a library and set of tools to handle documents in the DjVu format. An attacker could crash document viewers and possibly execute arbitrary code through crafted DjVu files. . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-2667-1
Several security issues were fixed in LibreOffice.. =========================================================================Ubuntu Security Notice USN-2793-1 November 05, 2015 libreoffice vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 15.04 - Ubuntu 14.04 LTS - Ubuntu 12.04 LTS Summary: Several security issues were fixed in LibreOffice. Software Description: - libreoffice: Office productivity suite Details: Federico Scrinzi discovered that LibreOffice incorrectly handled documents inserted into Writer or Calc via links. If a user were tricked into opening a specially crafted document, a remote attacker could possibly obtain the contents of arbitrary files. (CVE-2015-4551) It was discovered that LibreOffice incorrectly handled PrinterSetup data stored in ODF files. If a user were tricked into opening a specially crafted ODF document, a remote attacker could cause LibreOffice to crash, and possibly execute arbitrary code. (CVE-2015-5212) It was discovered that LibreOffice incorrectly handled the number of pieces in DOC files. If a user were tricked into opening a specially crafted DOC document, a remote attacker could cause LibreOffice to crash, and possibly execute arbitrary code. (CVE-2015-5213) It was discovered that LibreOffice incorrectly handled bookmarks in DOC files. If a user were tricked into opening a specially crafted DOC document, a remote attacker could cause LibreOffice to crash, and possibly execute arbitrary code. (CVE-2015-5214) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 15.04: libreoffice-core 1:4.4.6~rc3-0ubuntu1 Ubuntu 14.04 LTS: libreoffice-core 1:4.2.8-0ubuntu3 Ubuntu 12.04 LTS: libreoffice-core 1:3.5.7-0ubuntu9 After a standard system update you need to restart LibreOffice tomake all the necessary changes. References: https://ubuntu.com/security/notices/USN-2793-1 CVE-2015-4551, CVE-2015-5212, CVE-2015-5213, CVE-2015-5214 Package Information: https://launchpad.net/ubuntu/+source/libreoffice/1:4.4.6~rc3-0ubuntu1 https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu3 https://launchpad.net/ubuntu/+source/libreoffice/1:3.5.7-0ubuntu9 . Multiple vulnerabilities have been addressed in LibreOffice across different Ubuntu distributions. Ensure your software is updated for enhanced security.. LibreOffice Update, Ubuntu Security, Document Handling Issues. . Severity: Critical. LinuxSecurity.com Team
New KDE 3.1.1a packages are available for Slackware 9.0 which fix a security problem with the handling of PS and PDF documents.. [slackware-security] Updated KDE packages available New KDE 3.1.1a packages are available for Slackware 9.0 which fix a security problem with the handling of PS and PDF documents. Here are the details from the Slackware 9.0 ChangeLog: +--------------------------+ Thu Apr 17 15:32:15 PDT 2003 patches/packages/kde/*: Upgraded to KDE 3.1.1a. Also included in this directory are a rebuild of Qt (linked with Xft2 rather than Xft1), an updated aRts package (the aRts sound server is a component of KDE, but ships as part of Slackware's L series), and kdevelop-3.0a4a. Note that this update addresses a security problem with KDE's handling of PostScript documents. This is the overview of the problem from the KDE site: KDE uses Ghostscript software for processing of PostScript (PS) and PDF files in a way that allows for the execution of arbitrary commands that can be contained in such files. An attacker can prepare a malicious PostScript or PDF file which will provide the attacker with access to the victim's account and privileges when the victim opens this malicious file for viewing or when the victim browses a directory containing such malicious file and has file previews enabled. An attacker can provide malicious files remotely to a victim in an e-mail, as part of a webpage, via an ftp server and possible other means. We recommend that sites running KDE install this update. Please note that the change from Xft1 to Xft2 has changed the available fonts in Konsole (and presumably elsewhere), and that Xft2 seems unable to display the Linux Console font that was previously Slackware's default. Also, it doesn't handle gamma correction when displaying fonts against a black background, so we've had to change the default to black fonts on a white background (this is Konsole's default). This creates an additional issue withcertain file types displayed as bold white by /etc/DIR_COLORS becoming invisible in directory listings. A workaround is to comment out these lines (or change to a different color): .mpg 01;37 # movie formats .avi 01;37 .mov 01;37 (* Security fix *) patches/packages/kdei/*: New internationalization packages for KDE 3.1.1a. +--------------------------+ WHERE TO FIND THE NEW PACKAGES: +-----------------------------+ Updated packages for Slackware 9.0: MD5 SIGNATURES: +-------------+ Here are the md5sums for the packages: Slackware 9.0 packages: a4703d36ada98b2cf4f007831c345e71 arts-1.1.1-i386-1.tgz 84dee1d245b4a6a20cd863802cdb5585 kdeaddons-3.1.1-i386-1.tgz 41e728989a1607f0d1e59646299eaf5c kdeadmin-3.1.1-i386-1.tgz b78695f2fc29620b1042ed588168a0ce kdeartwork-3.1.1-i386-1.tgz fb8c6bc0b62e93c9cd0bc909184396fb kdebase-3.1.1a-i386-1.tgz b1bdcb88a6b063652dd1ccc39c185ea9 kdebindings-3.1.1-i386-1.tgz 984b511797675a0a656f61b13dab55ee kdeedu-3.1.1-i386-1.tgz 4d50f069d411d6ca25c929d1912cacef kdegames-3.1.1-i386-1.tgz 8d2d16f700606679f9c6f910cdfe8866 kdegraphics-3.1.1a-i386-1.tgz b5801384f120c0091fe424184f927747 kdelibs-3.1.1a-i386-1.tgz 9153f3c96a342bc028c1d3d1817d9bd6 kdemultimedia-3.1.1-i386-1.tgz e00a3cc3619021b4d1729fad8df70086 kdenetwork-3.1.1-i386-1.tgz 7a20c02d86b0fd944e51d3fa6e4c52cb kdepim-3.1.1-i386-1.tgz 6fb982e85cf99f1ad33eac381e9344d3 kdesdk-3.1.1-i386-1.tgz 49d7ff0c5043baa45d849e04671daf6e kdetoys-3.1.1-i386-1.tgz 547b68096327504b0368b979654b7639 kdeutils-3.1.1-i386-1.tgz 7a8716caa31054e3aa4f12d1bc80483a kdevelop-3.0a4a-i386-1.tgz c54f79a75a01e7b3947797eaf814045a koffice-1.2.1-i386-3.tgz abcd31460c04e7f7f2aa81153c4f1281 qt-3.1.2-i386-3.tgz 45b6b7d89d801925d6abe94f48042c5a quanta-3.1.1-i386-1.tgz INSTALLATION INSTRUCTIONS: +------------------------+ As root, use upgradepkg to upgrade to the new packages: upgradepkg *.tgz +-----+ Slackware Linux Security Team slackware
Get the latest Linux and open source security news straight to your inbox.