Updated libreoffice packages fix security vulnerability
Publication date: 10 Nov 2015Modification date: 10 Nov 2015
Type: security
Affected Mageia releases : 5
CVE: CVE-2015-4551 , CVE-2015-5212 , CVE-2015-5213 , CVE-2015-5214
Description
Federico Scrinzi discovered that LibreOffice incorrectly handled documents inserted into Writer or Calc via links. If a user were tricked into opening a specially crafted document, a remote attacker could possibly obtain the contents of arbitrary files (CVE-2015-4551). It was discovered that LibreOffice incorrectly handled PrinterSetup data stored in ODF files. If a user were tricked into opening a specially crafted ODF document, a remote attacker could cause LibreOffice to crash, and possibly execute arbitrary code.(CVE-2015-5212). It was discovered that LibreOffice incorrectly handled the number of pieces in DOC files. If a user were tricked into opening a specially crafted DOC document, a remote attacker could cause LibreOffice to crash, and possibly execute arbitrary code (CVE-2015-5213). It was discovered that LibreOffice incorrectly handled bookmarks in DOC files. If a user were tricked into opening a specially crafted DOC document, a remote attacker could cause LibreOffice to crash, and possibly execute arbitrary code (CVE-2015-5214). LibreOffice has been updated to version 4.4.6, which fixes these issues as well as several other bugs.
References
- https://bugs.mageia.org/show_bug.cgi?id=17097
- https://www.libreoffice.org/about-us/security/advisories/cve-2015-4551/
- https://www.libreoffice.org/about-us/security/advisories/cve-2015-5212/
- https://www.libreoffice.org/about-us/security/advisories/cve-2015-5213/
- https://www.libreoffice.org/about-us/security/advisories/cve-2015-5214/
- http://download.documentfoundation.org/libreoffice/src/bugs-changelog-libreoffice-4-4-4-release-4.4.4.1.log
- http://download.documentfoundation.org/libreoffice/src/bugs-changelog-libreoffice-4-4-4-release-4.4.4.2.log
- http://download.documentfoundation.org/libreoffice/src/bugs-changelog-libreoffice-4-4-4-release-4.4.4.3.log
- http://download.documentfoundation.org/libreoffice/src/bugs-changelog-libreoffice-4-4-5-release-4.4.5.1.log
- http://download.documentfoundation.org/libreoffice/src/bugs-changelog-libreoffice-4-4-5-release-4.4.5.2.log
- http://download.documentfoundation.org/libreoffice/src/bugs-changelog-libreoffice-4-4-6-release-4.4.6.1.log
- http://download.documentfoundation.org/libreoffice/src/bugs-changelog-libreoffice-4-4-6-release-4.4.6.2.log
- http://download.documentfoundation.org/libreoffice/src/bugs-changelog-libreoffice-4-4-6-release-4.4.6.3.log
- http://www.ubuntu.com/usn/usn-2793-1/
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-4551
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-5212
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-5213
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-5214
SRPMS
5/core
- libreoffice-4.4.6.3-2.2.mga5