MGASA-2015-0441
Dashboard / Vulnerabilities / MGASA-2015-0441
MGASA-2015-0441
Summary: Updated libreoffice packages fix security vulnerability
Details: Federico Scrinzi discovered that LibreOffice incorrectly handled documents inserted into Writer or Calc via links. If a user were tricked into opening a specially crafted document, a remote attacker could possibly obtain the contents of arbitrary files (CVE-2015-4551). It was discovered that LibreOffice incorrectly handled PrinterSetup data stored in ODF files. If a user were tricked into opening a specially crafted ODF document, a remote attacker could cause LibreOffice to crash, and possibly execute arbitrary code.(CVE-2015-5212). It was discovered that LibreOffice incorrectly handled the number of pieces in DOC files. If a user were tricked into opening a specially crafted DOC document, a remote attacker could cause LibreOffice to crash, and possibly execute arbitrary code (CVE-2015-5213). It was discovered that LibreOffice incorrectly handled bookmarks in DOC files. If a user were tricked into opening a specially crafted DOC document, a remote attacker could cause LibreOffice to crash, and possibly execute arbitrary code (CVE-2015-5214). LibreOffice has been updated to version 4.4.6, which fixes these issues as well as several other bugs.
References: https://advisories.mageia.org/MGASA-2015-0441.html, https://bugs.mageia.org/show_bug.cgi?id=17097, https://www.libreoffice.org/about-us/security/advisories/cve-2015-4551/, https://www.libreoffice.org/about-us/security/advisories/cve-2015-5212/, https://www.libreoffice.org/about-us/security/advisories/cve-2015-5213/, https://www.libreoffice.org/about-us/security/advisories/cve-2015-5214/, http://download.documentfoundation.org/libreoffice/src/bugs-changelog-libreoffice-4-4-4-release-4.4.4.1.log, http://download.documentfoundation.org/libreoffice/src/bugs-changelog-libreoffice-4-4-4-release-4.4.4.2.log, http://download.documentfoundation.org/libreoffice/src/bugs-changelog-libreoffice-4-4-4-release-4.4.4.3.log, http://download.documentfoundation.org/libreoffice/src/bugs-changelog-libreoffice-4-4-5-release-4.4.5.1.log, http://download.documentfoundation.org/libreoffice/src/bugs-changelog-libreoffice-4-4-5-release-4.4.5.2.log, http://download.documentfoundation.org/libreoffice/src/bugs-changelog-libreoffice-4-4-6-release-4.4.6.1.log, http://download.documentfoundation.org/libreoffice/src/bugs-changelog-libreoffice-4-4-6-release-4.4.6.2.log, http://download.documentfoundation.org/libreoffice/src/bugs-changelog-libreoffice-4-4-6-release-4.4.6.3.log, http://www.ubuntu.com/usn/usn-2793-1/
Affected packages
Package
Name: libreoffice
Purl: pkg:rpm/mageia/libreoffice?arch=source&distro=mageia-5
Affected ranges
Type: ECOSYSTEM
Events:
