SUSE-SU-2022:3602-1
Dashboard / Vulnerabilities / SUSE-SU-2022:3602-1
SUSE-SU-2022:3602-1
Summary: Security update for libreoffice
Details: This update for libreoffice fixes the following issues: Updated to version 7.3.6.2 (jsc#SLE-23448): - CVE-2022-3140: Fixed macro URL arbitrary script execution (bsc#1203209). - CVE-2022-26305: Fixed execution of untrusted Macros due to improper certificate validation (bsc#1201868). - CVE-2022-26307: Fixed weak Master Keys in password storage (bsc#1201872).
References: https://www.suse.com/support/update/announcement/2022/suse-su-20223602-1/, https://bugzilla.suse.com/1201868, https://bugzilla.suse.com/1201872, https://bugzilla.suse.com/1203209, https://www.suse.com/security/cve/CVE-2022-26305, https://www.suse.com/security/cve/CVE-2022-26307, https://www.suse.com/security/cve/CVE-2022-3140
Affected packages
Package
Name: libreoffice
Purl: pkg:rpm/suse/libreoffice&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP5
Affected ranges
Type: ECOSYSTEM
Events:
