MGASA-2015-0441

Source
https://advisories.mageia.org/MGASA-2015-0441.html
Import Source
https://advisories.mageia.org/MGASA-2015-0441.json
JSON Data
https://api.test.osv.dev/v1/vulns/MGASA-2015-0441
Related
Published
2015-11-10T21:26:39Z
Modified
2015-11-10T21:19:50Z
Summary
Updated libreoffice packages fix security vulnerability
Details

Federico Scrinzi discovered that LibreOffice incorrectly handled documents inserted into Writer or Calc via links. If a user were tricked into opening a specially crafted document, a remote attacker could possibly obtain the contents of arbitrary files (CVE-2015-4551).

It was discovered that LibreOffice incorrectly handled PrinterSetup data stored in ODF files. If a user were tricked into opening a specially crafted ODF document, a remote attacker could cause LibreOffice to crash, and possibly execute arbitrary code.(CVE-2015-5212).

It was discovered that LibreOffice incorrectly handled the number of pieces in DOC files. If a user were tricked into opening a specially crafted DOC document, a remote attacker could cause LibreOffice to crash, and possibly execute arbitrary code (CVE-2015-5213).

It was discovered that LibreOffice incorrectly handled bookmarks in DOC files. If a user were tricked into opening a specially crafted DOC document, a remote attacker could cause LibreOffice to crash, and possibly execute arbitrary code (CVE-2015-5214).

LibreOffice has been updated to version 4.4.6, which fixes these issues as well as several other bugs.

References
Credits

Affected packages

Mageia:5 / libreoffice

Package

Name
libreoffice
Purl
pkg:rpm/mageia/libreoffice?distro=mageia-5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.4.6.3-2.2.mga5

Ecosystem specific

{
    "section": "core"
}