SUSE-SU-2019:2003-1
Dashboard / Vulnerabilities / SUSE-SU-2019:2003-1
SUSE-SU-2019:2003-1
Summary: Security update for libreoffice
Details: This update for libreoffice fixes the following issues: LibreOffice was updated to 6.2.5.2 (fate#327121). Security issue fixed: - CVE-2018-16858: LibreOffice was vulnerable to a directory traversal attack which could be used to execute arbitrary macros bundled with a document. An attacker could craft a document, which when opened by LibreOffice, would execute a Python method from a script in any arbitrary file system location, specified relative to the LibreOffice install location. (bsc#1124062) Other bugfixes: - If there is no firebird engine we still need java to run hsqldb (bsc#1135189) - Require firebird as default driver for base if enabled - PPTX: Rectangle turns from green to blue and loses transparency when transparency is set (bsc1135228) - Slide deck compression doesn't, hmm, compress too much (bsc#1127760) - Psychedelic graphics in LibreOffice (but not PowerPoint) (bsc#1124869) - Image from PPTX shown in a square, not a circle (bsc#1121874) - Switch to the new web based help system bsc#1116451 - Enable new approach for mariadb connector again - PPTX: SmartArt: Basic rendering of the Organizational Chart (bsc#1112114) - PPTX: SmartArt: Basic rendering of Accent Process and Continuous Block Process (bsc#1112113) - Saving a new document can silently overwrite an existing document (bsc#1117300) - Install also C++ libreofficekit headers bsc#1117195 - Chart in PPTX lacks color and is too large (bsc#882383) - PPTX: SmartArt: Basic rendering of several list types (bsc#1112112) - PPTX: Charts having weird/darker/ugly background versus Office 365 and strange artefacts where overlapping (bsc#1110348)
References: https://www.suse.com/support/update/announcement/2019/suse-su-20192003-1/, https://bugzilla.suse.com/1110348, https://bugzilla.suse.com/1112112, https://bugzilla.suse.com/1112113, https://bugzilla.suse.com/1112114, https://bugzilla.suse.com/1116451, https://bugzilla.suse.com/1117195, https://bugzilla.suse.com/1117300, https://bugzilla.suse.com/1121874, https://bugzilla.suse.com/1123131, https://bugzilla.suse.com/1123455, https://bugzilla.suse.com/1124062, https://bugzilla.suse.com/1124658, https://bugzilla.suse.com/1124869, https://bugzilla.suse.com/1127760, https://bugzilla.suse.com/1127857, https://bugzilla.suse.com/1128845, https://bugzilla.suse.com/1135189, https://bugzilla.suse.com/1135228, https://bugzilla.suse.com/882383, https://www.suse.com/security/cve/CVE-2018-16858
Affected packages
Package
Name: libreoffice
Purl: pkg:rpm/suse/libreoffice&distro=SUSE%20Linux%20Enterprise%20Workstation%20Extension%2015%20SP1
Affected ranges
Type: ECOSYSTEM
Events:
