openSUSE-SU-2019:2057-1
Dashboard / Vulnerabilities / openSUSE-SU-2019:2057-1
openSUSE-SU-2019:2057-1
Summary: Security update for libreoffice
Details: This update for libreoffice fixes the following issues: Security issues fixed: - CVE-2019-9849: Disabled fetching remote bullet graphics in 'stealth mode' (bsc#1141861). - CVE-2019-9848: Fixed an arbitrary script execution via LibreLogo (bsc#1141862). - CVE-2019-9851: Fixed LibreLogo global-event script execution issue (bsc#1146105). - CVE-2019-9852: Fixed insufficient URL encoding flaw in allowed script location check (bsc#1146107). - CVE-2019-9850: Fixed insufficient URL validation that allowed LibreLogo script execution (bsc#1146098). Non-security issue fixed: - SmartArt: Basic rendering of Trapezoid List (bsc#1133534) This update was imported from the SUSE:SLE-15:Update update project.
References: https://lists.opensuse.org/archives/list/[email protected]/thread/I7HPM7NSWXIAXQHQUBQWFSBX63DT47EP/#I7HPM7NSWXIAXQHQUBQWFSBX63DT47EP, https://bugzilla.suse.com/1133534, https://bugzilla.suse.com/1141861, https://bugzilla.suse.com/1141862, https://bugzilla.suse.com/1146098, https://bugzilla.suse.com/1146105, https://bugzilla.suse.com/1146107, https://www.suse.com/security/cve/CVE-2019-9848, https://www.suse.com/security/cve/CVE-2019-9849, https://www.suse.com/security/cve/CVE-2019-9850, https://www.suse.com/security/cve/CVE-2019-9851, https://www.suse.com/security/cve/CVE-2019-9852
Affected packages
Package
Name: libreoffice
Purl: pkg:rpm/opensuse/libreoffice&distro=openSUSE%20Leap%2015.0
Affected ranges
Type: ECOSYSTEM
Events:
