SUSE-SU-2019:2401-1
Dashboard / Vulnerabilities / SUSE-SU-2019:2401-1
SUSE-SU-2019:2401-1
Summary: Security update for libreoffice
Details: This update for libreoffice to version 6.2.7.1 fixes the following issues: Security issues fixed: - CVE-2019-9849: Disabled fetching remote bullet graphics in 'stealth mode' (bsc#1141861). - CVE-2019-9848: Fixed an arbitrary script execution via LibreLogo (bsc#1141862). - CVE-2019-9851: Fixed LibreLogo global-event script execution issue (bsc#1146105). - CVE-2019-9852: Fixed insufficient URL encoding flaw in allowed script location check (bsc#1146107). - CVE-2019-9850: Fixed insufficient URL validation that allowed LibreLogo script execution (bsc#1146098). - CVE-2019-9854: Fixed unsafe URL assembly flaw (bsc#1149944). - CVE-2019-9855: Fixed path equivalence handling flaw (bsc#1149943) Non-security issue fixed: - SmartArt: Basic rendering of Trapezoid List (bsc#1133534)
References: https://www.suse.com/support/update/announcement/2019/suse-su-20192401-1/, https://bugzilla.suse.com/1133534, https://bugzilla.suse.com/1141861, https://bugzilla.suse.com/1141862, https://bugzilla.suse.com/1146098, https://bugzilla.suse.com/1146105, https://bugzilla.suse.com/1146107, https://bugzilla.suse.com/1149943, https://bugzilla.suse.com/1149944, https://www.suse.com/security/cve/CVE-2019-9848, https://www.suse.com/security/cve/CVE-2019-9849, https://www.suse.com/security/cve/CVE-2019-9850, https://www.suse.com/security/cve/CVE-2019-9851, https://www.suse.com/security/cve/CVE-2019-9852, https://www.suse.com/security/cve/CVE-2019-9854, https://www.suse.com/security/cve/CVE-2019-9855
Affected packages
Package
Name: libreoffice
Purl: pkg:rpm/suse/libreoffice&distro=SUSE%20Linux%20Enterprise%20Desktop%2012%20SP4
Affected ranges
Type: ECOSYSTEM
Events:
