USN-2793-1
Dashboard / Vulnerabilities / USN-2793-1
USN-2793-1
Summary: libreoffice vulnerabilities
Details: Federico Scrinzi discovered that LibreOffice incorrectly handled documents inserted into Writer or Calc via links. If a user were tricked into opening a specially crafted document, a remote attacker could possibly obtain the contents of arbitrary files. (CVE-2015-4551) It was discovered that LibreOffice incorrectly handled PrinterSetup data stored in ODF files. If a user were tricked into opening a specially crafted ODF document, a remote attacker could cause LibreOffice to crash, and possibly execute arbitrary code. (CVE-2015-5212) It was discovered that LibreOffice incorrectly handled the number of pieces in DOC files. If a user were tricked into opening a specially crafted DOC document, a remote attacker could cause LibreOffice to crash, and possibly execute arbitrary code. (CVE-2015-5213) It was discovered that LibreOffice incorrectly handled bookmarks in DOC files. If a user were tricked into opening a specially crafted DOC document, a remote attacker could cause LibreOffice to crash, and possibly execute arbitrary code. (CVE-2015-5214)
References: https://ubuntu.com/security/notices/USN-2793-1, https://ubuntu.com/security/CVE-2015-4551, https://ubuntu.com/security/CVE-2015-5212, https://ubuntu.com/security/CVE-2015-5213, https://ubuntu.com/security/CVE-2015-5214
Affected packages
Package
Name: libreoffice
Purl: pkg:deb/ubuntu/libreoffice@1:4.2.8-0ubuntu3?arch=source&distro=trusty
Affected ranges
Type: ECOSYSTEM
Events:
