Important: libreoffice security fix update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2024:1514", "synopsis": "Important: libreoffice security fix update", "severity": "SEVERITY_IMPORTANT", "topic": "An update is available for libreoffice.\nThis update affects Rocky Linux 8.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "LibreOffice is an open source, community-developed office productivity suite. It includes key desktop applications, such as a word processor, a spreadsheet, a presentation manager, a formula editor, and a drawing program. LibreOffice replaces OpenOffice and provides a similar but enhanced and extended office suite.\n\nSecurity Fix(es):\n\n* libreoffice: Improper Input Validation leading to arbitrary gstreamer plugin execution (CVE-2023-6185)\n\n* libreoffice: Insufficient macro permission validation leading to macro execution (CVE-2023-6186)", "solution": null, "affectedProducts": ["Rocky Linux 8"], "fixes": [{"ticket": "2254003", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2254003", "description": ""}, {"ticket": "2254005", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2254005", "description": ""}], "cves": [{"name": "CVE-2023-6185", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2023-6185", "cvss3ScoringVector": "UNKNOWN", "cvss3BaseScore": "UNKNOWN", "cwe": "UNKNOWN"}, {"name": "CVE-2023-6186", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2023-6186", "cvss3ScoringVector": "UNKNOWN", "cvss3BaseScore": "UNKNOWN", "cwe": "UNKNOWN"}], "references": [], "publishedAt": "2024-03-27T04:34:32.999941Z", "rpms": {"Rocky Linux 8": {"nvras": ["autocorr-cs-1:6.4.7.2-16.el8_9.noarch.rpm", "autocorr-af-1:6.4.7.2-16.el8_9.noarch.rpm", "autocorr-bg-1:6.4.7.2-16.el8_9.noarch.rpm", "autocorr-ca-1:6.4.7.2-16.el8_9.noarch.rpm","autocorr-da-1:6.4.7.2-16.el8_9.noarch.rpm", "autocorr-de-1:6.4.7.2-16.el8_9.noarch.rpm", "autocorr-en-1:6.4.7.2-16.el8_9.noarch.rpm", "autocorr-es-1:6.4.7.2-16.el8_9.noarch.rpm", "autocorr-fa-1:6.4.7.2-16.el8_9.noarch.rpm", "autocorr-fi-1:6.4.7.2-16.el8_9.noarch.rpm", "autocorr-fr-1:6.4.7.2-16.el8_9.noarch.rpm", "autocorr-ga-1:6.4.7.2-16.el8_9.noarch.rpm", "autocorr-hr-1:6.4.7.2-16.el8_9.noarch.rpm", "autocorr-hu-1:6.4.7.2-16.el8_9.noarch.rpm", "autocorr-is-1:6.4.7.2-16.el8_9.noarch.rpm", "autocorr-it-1:6.4.7.2-16.el8_9.noarch.rpm", "autocorr-ja-1:6.4.7.2-16.el8_9.noarch.rpm", "autocorr-ko-1:6.4.7.2-16.el8_9.noarch.rpm", "autocorr-lb-1:6.4.7.2-16.el8_9.noarch.rpm", "autocorr-lt-1:6.4.7.2-16.el8_9.noarch.rpm", "autocorr-mn-1:6.4.7.2-16.el8_9.noarch.rpm", "autocorr-nl-1:6.4.7.2-16.el8_9.noarch.rpm", "autocorr-pl-1:6.4.7.2-16.el8_9.noarch.rpm", "autocorr-pt-1:6.4.7.2-16.el8_9.noarch.rpm", "autocorr-ro-1:6.4.7.2-16.el8_9.noarch.rpm", "autocorr-ru-1:6.4.7.2-16.el8_9.noarch.rpm", "autocorr-sk-1:6.4.7.2-16.el8_9.noarch.rpm", "autocorr-sl-1:6.4.7.2-16.el8_9.noarch.rpm", "autocorr-sr-1:6.4.7.2-16.el8_9.noarch.rpm", "autocorr-sv-1:6.4.7.2-16.el8_9.noarch.rpm", "autocorr-tr-1:6.4.7.2-16.el8_9.noarch.rpm", "autocorr-vi-1:6.4.7.2-16.el8_9.noarch.rpm", "autocorr-zh-1:6.4.7.2-16.el8_9.noarch.rpm", "libreoffice-1:6.4.7.2-16.el8_9.src.rpm", "libreoffice-1:6.4.7.2-16.el8_9.x86_64.rpm", "libreoffice-base-1:6.4.7.2-16.el8_9.x86_64.rpm", "libreoffice-base-debuginfo-1:6.4.7.2-16.el8_9.x86_64.rpm", "libreoffice-calc-1:6.4.7.2-16.el8_9.aarch64.rpm", "libreoffice-calc-1:6.4.7.2-16.el8_9.x86_64.rpm", "libreoffice-calc-debuginfo-1:6.4.7.2-16.el8_9.aarch64.rpm", "libreoffice-calc-debuginfo-1:6.4.7.2-16.el8_9.x86_64.rpm", "libreoffice-core-1:6.4.7.2-16.el8_9.aarch64.rpm", "libreoffice-core-1:6.4.7.2-16.el8_9.x86_64.rpm", "libreoffice-core-debuginfo-1:6.4.7.2-16.el8_9.aarch64.rpm", "libreoffice-core-debuginfo-1:6.4.7.2-16.el8_9.x86_64.rpm", "libreoffice-data-1:6.4.7.2-16.el8_9.noarch.rpm","libreoffice-debuginfo-1:6.4.7.2-16.el8_9.aarch64.rpm", "libreoffice-debuginfo-1:6.4.7.2-16.el8_9.x86_64.rpm", "libreoffice-debugsource-1:6.4.7.2-16.el8_9.aarch64.rpm", "libreoffice-debugsource-1:6.4.7.2-16.el8_9.x86_64.rpm", "libreoffice-draw-1:6.4.7.2-16.el8_9.x86_64.rpm", "libreoffice-emailmerge-1:6.4.7.2-16.el8_9.x86_64.rpm", "libreoffice-filters-1:6.4.7.2-16.el8_9.x86_64.rpm", "libreoffice-gdb-debug-support-1:6.4.7.2-16.el8_9.x86_64.rpm", "libreoffice-graphicfilter-1:6.4.7.2-16.el8_9.aarch64.rpm", "libreoffice-graphicfilter-1:6.4.7.2-16.el8_9.x86_64.rpm", "libreoffice-graphicfilter-debuginfo-1:6.4.7.2-16.el8_9.aarch64.rpm", "libreoffice-graphicfilter-debuginfo-1:6.4.7.2-16.el8_9.x86_64.rpm", "libreoffice-gtk3-1:6.4.7.2-16.el8_9.x86_64.rpm", "libreoffice-gtk3-debuginfo-1:6.4.7.2-16.el8_9.x86_64.rpm", "libreoffice-help-ar-1:6.4.7.2-16.el8_9.x86_64.rpm", "libreoffice-help-bg-1:6.4.7.2-16.el8_9.x86_64.rpm", "libreoffice-help-bn-1:6.4.7.2-16.el8_9.x86_64.rpm", "libreoffice-help-ca-1:6.4.7.2-16.el8_9.x86_64.rpm", "libreoffice-help-cs-1:6.4.7.2-16.el8_9.x86_64.rpm", "libreoffice-help-da-1:6.4.7.2-16.el8_9.x86_64.rpm", "libreoffice-help-de-1:6.4.7.2-16.el8_9.x86_64.rpm", "libreoffice-help-dz-1:6.4.7.2-16.el8_9.x86_64.rpm", "libreoffice-help-el-1:6.4.7.2-16.el8_9.x86_64.rpm", "libreoffice-help-en-1:6.4.7.2-16.el8_9.aarch64.rpm", "libreoffice-help-en-1:6.4.7.2-16.el8_9.x86_64.rpm", "libreoffice-help-es-1:6.4.7.2-16.el8_9.x86_64.rpm", "libreoffice-help-et-1:6.4.7.2-16.el8_9.x86_64.rpm", "libreoffice-help-eu-1:6.4.7.2-16.el8_9.x86_64.rpm", "libreoffice-help-fi-1:6.4.7.2-16.el8_9.x86_64.rpm", "libreoffice-help-fr-1:6.4.7.2-16.el8_9.x86_64.rpm", "libreoffice-help-gl-1:6.4.7.2-16.el8_9.x86_64.rpm", "libreoffice-help-gu-1:6.4.7.2-16.el8_9.x86_64.rpm", "libreoffice-help-he-1:6.4.7.2-16.el8_9.x86_64.rpm", "libreoffice-help-hi-1:6.4.7.2-16.el8_9.x86_64.rpm", "libreoffice-help-hr-1:6.4.7.2-16.el8_9.x86_64.rpm", "libreoffice-help-hu-1:6.4.7.2-16.el8_9.x86_64.rpm", "libreoffice-help-id-1:6.4.7.2-16.el8_9.x86_64.rpm","libreoffice-help-it-1:6.4.7.2-16.el8_9.x86_64.rpm", "libreoffice-help-ja-1:6.4.7.2-16.el8_9.x86_64.rpm", "libreoffice-help-ko-1:6.4.7.2-16.el8_9.x86_64.rpm", "libreoffice-help-lt-1:6.4.7.2-16.el8_9.x86_64.rpm", "libreoffice-help-lv-1:6.4.7.2-16.el8_9.x86_64.rpm", "libreoffice-help-nb-1:6.4.7.2-16.el8_9.x86_64.rpm", "libreoffice-help-nl-1:6.4.7.2-16.el8_9.x86_64.rpm", "libreoffice-help-nn-1:6.4.7.2-16.el8_9.x86_64.rpm", "libreoffice-help-pl-1:6.4.7.2-16.el8_9.x86_64.rpm", "libreoffice-help-pt-BR-1:6.4.7.2-16.el8_9.x86_64.rpm", "libreoffice-help-pt-PT-1:6.4.7.2-16.el8_9.x86_64.rpm", "libreoffice-help-ro-1:6.4.7.2-16.el8_9.x86_64.rpm", "libreoffice-help-ru-1:6.4.7.2-16.el8_9.x86_64.rpm", "libreoffice-help-si-1:6.4.7.2-16.el8_9.x86_64.rpm", "libreoffice-help-sk-1:6.4.7.2-16.el8_9.x86_64.rpm", "libreoffice-help-sl-1:6.4.7.2-16.el8_9.x86_64.rpm", "libreoffice-help-sv-1:6.4.7.2-16.el8_9.x86_64.rpm", "libreoffice-help-ta-1:6.4.7.2-16.el8_9.x86_64.rpm", "libreoffice-help-tr-1:6.4.7.2-16.el8_9.x86_64.rpm", "libreoffice-help-uk-1:6.4.7.2-16.el8_9.x86_64.rpm", "libreoffice-help-zh-Hans-1:6.4.7.2-16.el8_9.x86_64.rpm", "libreoffice-help-zh-Hant-1:6.4.7.2-16.el8_9.x86_64.rpm", "libreoffice-impress-1:6.4.7.2-16.el8_9.aarch64.rpm", "libreoffice-impress-1:6.4.7.2-16.el8_9.x86_64.rpm", "libreoffice-impress-debuginfo-1:6.4.7.2-16.el8_9.aarch64.rpm", "libreoffice-impress-debuginfo-1:6.4.7.2-16.el8_9.x86_64.rpm", "libreofficekit-1:6.4.7.2-16.el8_9.x86_64.rpm", "libreofficekit-debuginfo-1:6.4.7.2-16.el8_9.x86_64.rpm", "libreoffice-langpack-af-1:6.4.7.2-16.el8_9.x86_64.rpm", "libreoffice-langpack-ar-1:6.4.7.2-16.el8_9.x86_64.rpm", "libreoffice-langpack-as-1:6.4.7.2-16.el8_9.x86_64.rpm", "libreoffice-langpack-bg-1:6.4.7.2-16.el8_9.x86_64.rpm", "libreoffice-langpack-bn-1:6.4.7.2-16.el8_9.x86_64.rpm", "libreoffice-langpack-br-1:6.4.7.2-16.el8_9.x86_64.rpm", "libreoffice-langpack-ca-1:6.4.7.2-16.el8_9.x86_64.rpm", "libreoffice-langpack-cs-1:6.4.7.2-16.el8_9.x86_64.rpm", "libreoffice-langpack-cy-1:6.4.7.2-16.el8_9.x86_64.rpm","libreoffice-langpack-da-1:6.4.7.2-16.el8_9.x86_64.rpm", "libreoffice-langpack-de-1:6.4.7.2-16.el8_9.x86_64.rpm", "libreoffice-langpack-dz-1:6.4.7.2-16.el8_9.x86_64.rpm", "libreoffice-langpack-el-1:6.4.7.2-16.el8_9.x86_64.rpm", "libreoffice-langpack-en-1:6.4.7.2-16.el8_9.aarch64.rpm", "libreoffice-langpack-en-1:6.4.7.2-16.el8_9.x86_64.rpm", "libreoffice-langpack-es-1:6.4.7.2-16.el8_9.x86_64.rpm", "libreoffice-langpack-et-1:6.4.7.2-16.el8_9.x86_64.rpm", "libreoffice-langpack-eu-1:6.4.7.2-16.el8_9.x86_64.rpm", "libreoffice-langpack-fa-1:6.4.7.2-16.el8_9.x86_64.rpm", "libreoffice-langpack-fi-1:6.4.7.2-16.el8_9.x86_64.rpm", "libreoffice-langpack-fr-1:6.4.7.2-16.el8_9.x86_64.rpm", "libreoffice-langpack-ga-1:6.4.7.2-16.el8_9.x86_64.rpm", "libreoffice-langpack-gl-1:6.4.7.2-16.el8_9.x86_64.rpm", "libreoffice-langpack-gu-1:6.4.7.2-16.el8_9.x86_64.rpm", "libreoffice-langpack-he-1:6.4.7.2-16.el8_9.x86_64.rpm", "libreoffice-langpack-hi-1:6.4.7.2-16.el8_9.x86_64.rpm", "libreoffice-langpack-hr-1:6.4.7.2-16.el8_9.x86_64.rpm", "libreoffice-langpack-hu-1:6.4.7.2-16.el8_9.x86_64.rpm", "libreoffice-langpack-id-1:6.4.7.2-16.el8_9.x86_64.rpm", "libreoffice-langpack-it-1:6.4.7.2-16.el8_9.x86_64.rpm", "libreoffice-langpack-ja-1:6.4.7.2-16.el8_9.x86_64.rpm", "libreoffice-langpack-kk-1:6.4.7.2-16.el8_9.x86_64.rpm", "libreoffice-langpack-kn-1:6.4.7.2-16.el8_9.x86_64.rpm", "libreoffice-langpack-ko-1:6.4.7.2-16.el8_9.x86_64.rpm", "libreoffice-langpack-lt-1:6.4.7.2-16.el8_9.x86_64.rpm", "libreoffice-langpack-lv-1:6.4.7.2-16.el8_9.x86_64.rpm", "libreoffice-langpack-mai-1:6.4.7.2-16.el8_9.x86_64.rpm", "libreoffice-langpack-ml-1:6.4.7.2-16.el8_9.x86_64.rpm", "libreoffice-langpack-mr-1:6.4.7.2-16.el8_9.x86_64.rpm", "libreoffice-langpack-nb-1:6.4.7.2-16.el8_9.x86_64.rpm", "libreoffice-langpack-nl-1:6.4.7.2-16.el8_9.x86_64.rpm", "libreoffice-langpack-nn-1:6.4.7.2-16.el8_9.x86_64.rpm", "libreoffice-langpack-nr-1:6.4.7.2-16.el8_9.x86_64.rpm", "libreoffice-langpack-nso-1:6.4.7.2-16.el8_9.x86_64.rpm","libreoffice-langpack-or-1:6.4.7.2-16.el8_9.x86_64.rpm", "libreoffice-langpack-pa-1:6.4.7.2-16.el8_9.x86_64.rpm", "libreoffice-langpack-pl-1:6.4.7.2-16.el8_9.x86_64.rpm", "libreoffice-langpack-pt-BR-1:6.4.7.2-16.el8_9.x86_64.rpm", "libreoffice-langpack-pt-PT-1:6.4.7.2-16.el8_9.x86_64.rpm", "libreoffice-langpack-ro-1:6.4.7.2-16.el8_9.x86_64.rpm", "libreoffice-langpack-ru-1:6.4.7.2-16.el8_9.x86_64.rpm", "libreoffice-langpack-si-1:6.4.7.2-16.el8_9.x86_64.rpm", "libreoffice-langpack-sk-1:6.4.7.2-16.el8_9.x86_64.rpm", "libreoffice-langpack-sl-1:6.4.7.2-16.el8_9.x86_64.rpm", "libreoffice-langpack-sr-1:6.4.7.2-16.el8_9.x86_64.rpm", "libreoffice-langpack-ss-1:6.4.7.2-16.el8_9.x86_64.rpm", "libreoffice-langpack-st-1:6.4.7.2-16.el8_9.x86_64.rpm", "libreoffice-langpack-sv-1:6.4.7.2-16.el8_9.x86_64.rpm", "libreoffice-langpack-ta-1:6.4.7.2-16.el8_9.x86_64.rpm", "libreoffice-langpack-te-1:6.4.7.2-16.el8_9.x86_64.rpm", "libreoffice-langpack-th-1:6.4.7.2-16.el8_9.x86_64.rpm", "libreoffice-langpack-tn-1:6.4.7.2-16.el8_9.x86_64.rpm", "libreoffice-langpack-tr-1:6.4.7.2-16.el8_9.x86_64.rpm", "libreoffice-langpack-ts-1:6.4.7.2-16.el8_9.x86_64.rpm", "libreoffice-langpack-uk-1:6.4.7.2-16.el8_9.x86_64.rpm", "libreoffice-langpack-ve-1:6.4.7.2-16.el8_9.x86_64.rpm", "libreoffice-langpack-xh-1:6.4.7.2-16.el8_9.x86_64.rpm", "libreoffice-langpack-zh-Hans-1:6.4.7.2-16.el8_9.x86_64.rpm", "libreoffice-langpack-zh-Hant-1:6.4.7.2-16.el8_9.x86_64.rpm", "libreoffice-langpack-zu-1:6.4.7.2-16.el8_9.x86_64.rpm", "libreoffice-math-1:6.4.7.2-16.el8_9.x86_64.rpm", "libreoffice-ogltrans-1:6.4.7.2-16.el8_9.aarch64.rpm", "libreoffice-ogltrans-1:6.4.7.2-16.el8_9.x86_64.rpm", "libreoffice-ogltrans-debuginfo-1:6.4.7.2-16.el8_9.aarch64.rpm", "libreoffice-ogltrans-debuginfo-1:6.4.7.2-16.el8_9.x86_64.rpm", "libreoffice-opensymbol-fonts-1:6.4.7.2-16.el8_9.noarch.rpm", "libreoffice-pdfimport-1:6.4.7.2-16.el8_9.aarch64.rpm", "libreoffice-pdfimport-1:6.4.7.2-16.el8_9.x86_64.rpm", "libreoffice-pdfimport-debuginfo-1:6.4.7.2-16.el8_9.aarch64.rpm","libreoffice-pdfimport-debuginfo-1:6.4.7.2-16.el8_9.x86_64.rpm", "libreoffice-pyuno-1:6.4.7.2-16.el8_9.aarch64.rpm", "libreoffice-pyuno-1:6.4.7.2-16.el8_9.x86_64.rpm", "libreoffice-pyuno-debuginfo-1:6.4.7.2-16.el8_9.aarch64.rpm", "libreoffice-pyuno-debuginfo-1:6.4.7.2-16.el8_9.x86_64.rpm", "libreoffice-sdk-1:6.4.7.2-16.el8_9.x86_64.rpm", "libreoffice-sdk-debuginfo-1:6.4.7.2-16.el8_9.x86_64.rpm", "libreoffice-sdk-doc-1:6.4.7.2-16.el8_9.x86_64.rpm", "libreoffice-ure-1:6.4.7.2-16.el8_9.aarch64.rpm", "libreoffice-ure-1:6.4.7.2-16.el8_9.x86_64.rpm", "libreoffice-ure-common-1:6.4.7.2-16.el8_9.noarch.rpm", "libreoffice-ure-debuginfo-1:6.4.7.2-16.el8_9.aarch64.rpm", "libreoffice-ure-debuginfo-1:6.4.7.2-16.el8_9.x86_64.rpm", "libreoffice-wiki-publisher-1:6.4.7.2-16.el8_9.x86_64.rpm", "libreoffice-writer-1:6.4.7.2-16.el8_9.aarch64.rpm", "libreoffice-writer-1:6.4.7.2-16.el8_9.x86_64.rpm", "libreoffice-writer-debuginfo-1:6.4.7.2-16.el8_9.aarch64.rpm", "libreoffice-writer-debuginfo-1:6.4.7.2-16.el8_9.x86_64.rpm", "libreoffice-x11-1:6.4.7.2-16.el8_9.x86_64.rpm", "libreoffice-x11-debuginfo-1:6.4.7.2-16.el8_9.x86_64.rpm", "libreoffice-xsltfilter-1:6.4.7.2-16.el8_9.x86_64.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. Patch addressing faulty input checks and macro access settings in LibreOffice on Rocky Linux 8. Significant vulnerabilities resolved.. LibreOffice Fix, Rocky Linux Update, Input Validation Issue, Security Risks, Macro Permission. . Severity: Important. LinuxSecurity.com Team
7.5.9.2. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2023-0d971cd6aa 2023-12-13 01:33:56.709109 -------------------------------------------------------------------------------- Name : libreoffice Product : Fedora 38 Version : 7.5.9.2 Release : 1.fc38 URL : https://www.libreoffice.org/ Summary : Free Software Productivity Suite Description : LibreOffice is an Open Source, community-developed, office productivity suite. It includes the key desktop applications, such as a word processor, spreadsheet, presentation manager, formula editor and drawing program, with a user interface and feature set similar to other office suites. Sophisticated and flexible, LibreOffice also works transparently with a variety of file formats, including Microsoft Office File Formats. -------------------------------------------------------------------------------- Update Information: 7.5.9.2 -------------------------------------------------------------------------------- ChangeLog: * Thu Dec 7 2023 Gwyn Ciesla - 1:7.5.9.2-1 - 7.5.9.2 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2254004 - CVE-2023-6185 libreoffice: Improper Input Validation leading to arbitrary gstreamer plugin execution [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2254004 [ 2 ] Bug #2254006 - CVE-2023-6186 libreoffice: Insufficient macro permission validation leading to macro execution [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2254006 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-0d971cd6aa' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the FedoraProject GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.