UBUNTU-CVE-2023-36268

Source
https://ubuntu.com/security/CVE-2023-36268
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2023/UBUNTU-CVE-2023-36268.json
JSON Data
https://api.test.osv.dev/v1/vulns/UBUNTU-CVE-2023-36268
Related
Published
2024-04-30T18:15:00Z
Modified
2025-01-29T04:56:04Z
Summary
[none]
Details

An issue in The Document Foundation Libreoffice v.7.4.7 allows a remote attacker to cause a denial of service via a crafted .ppt file.

References

Affected packages

Ubuntu:20.04:LTS / libreoffice

Package

Name
libreoffice
Purl
pkg:deb/ubuntu/libreoffice@1:6.4.7-0ubuntu0.20.04.13?arch=source&distro=focal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1:6.*

1:6.3.2-0ubuntu2
1:6.3.3-0ubuntu1
1:6.3.3-0ubuntu2
1:6.3.4-0ubuntu1
1:6.4.0-0ubuntu4
1:6.4.0-0ubuntu6
1:6.4.0-0ubuntu7
1:6.4.1-0ubuntu1
1:6.4.2-0ubuntu1
1:6.4.2-0ubuntu2
1:6.4.2-0ubuntu3
1:6.4.3-0ubuntu0.20.04.1
1:6.4.4-0ubuntu0.20.04.1
1:6.4.5-0ubuntu0.20.04.1
1:6.4.6-0ubuntu0.20.04.1
1:6.4.7-0ubuntu0.20.04.1
1:6.4.7-0ubuntu0.20.04.2
1:6.4.7-0ubuntu0.20.04.4
1:6.4.7-0ubuntu0.20.04.5
1:6.4.7-0ubuntu0.20.04.6
1:6.4.7-0ubuntu0.20.04.7
1:6.4.7-0ubuntu0.20.04.8
1:6.4.7-0ubuntu0.20.04.9
1:6.4.7-0ubuntu0.20.04.10
1:6.4.7-0ubuntu0.20.04.11
1:6.4.7-0ubuntu0.20.04.12
1:6.4.7-0ubuntu0.20.04.13

Ecosystem specific

{
    "ubuntu_priority": "low",
    "priority_reason": "Denial of service via resource exhaustion in a desktop application"
}

Ubuntu:22.04:LTS / libreoffice

Package

Name
libreoffice
Purl
pkg:deb/ubuntu/libreoffice@1:7.3.7-0ubuntu0.22.04.8?arch=source&distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1:7.*

1:7.2.1-0ubuntu3
1:7.2.2-0ubuntu0.21.10.1
1:7.2.3~rc2-0ubuntu1
1:7.2.4-0ubuntu1
1:7.2.5~rc1-0ubuntu2
1:7.2.5~rc2-0ubuntu1
1:7.3.1~rc2-0ubuntu1
1:7.3.1~rc3-0ubuntu1
1:7.3.2~rc1-0ubuntu2
1:7.3.2~rc2-0ubuntu1
1:7.3.2-0ubuntu1
1:7.3.2-0ubuntu2
1:7.3.3-0ubuntu0.22.04.1
1:7.3.4-0ubuntu0.22.04.1
1:7.3.5-0ubuntu0.22.04.1
1:7.3.6-0ubuntu0.22.04.1
1:7.3.6-0ubuntu0.22.04.2
1:7.3.7-0ubuntu0.22.04.1
1:7.3.7-0ubuntu0.22.04.2
1:7.3.7-0ubuntu0.22.04.3
1:7.3.7-0ubuntu0.22.04.4
1:7.3.7-0ubuntu0.22.04.5
1:7.3.7-0ubuntu0.22.04.6
1:7.3.7-0ubuntu0.22.04.7
1:7.3.7-0ubuntu0.22.04.8

Ecosystem specific

{
    "ubuntu_priority": "low",
    "priority_reason": "Denial of service via resource exhaustion in a desktop application"
}

Ubuntu:24.10 / libreoffice

Package

Name
libreoffice
Purl
pkg:deb/ubuntu/libreoffice@4:24.8.4-0ubuntu0.24.10.2?arch=source&distro=oracular

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

4:24.*

4:24.2.2-0ubuntu1
4:24.2.4~rc1-0ubuntu1
4:24.2.4~rc2-0ubuntu1
4:24.2.4-0ubuntu1
4:24.2.5~rc1-0ubuntu1
4:24.2.5-0ubuntu1
4:24.2.5-0ubuntu2
4:24.8.0-0ubuntu1
4:24.8.0-0ubuntu2
4:24.8.1-0ubuntu1
4:24.8.2-0ubuntu1
4:24.8.3-0ubuntu0.24.10.1
4:24.8.4-0ubuntu0.24.10.1
4:24.8.4-0ubuntu0.24.10.2

Ecosystem specific

{
    "ubuntu_priority": "low",
    "priority_reason": "Denial of service via resource exhaustion in a desktop application"
}

Ubuntu:24.04:LTS / libreoffice

Package

Name
libreoffice
Purl
pkg:deb/ubuntu/libreoffice@4:24.2.7-0ubuntu0.24.04.2?arch=source&distro=noble

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

4:7.*

4:7.6.2-0ubuntu1
4:7.6.3~rc1-0ubuntu2
4:7.6.3-0ubuntu3
4:7.6.4-0ubuntu1
4:7.6.4-0ubuntu3

4:24.*

4:24.2.0~rc1-0ubuntu1
4:24.2.1~rc1-0ubuntu1
4:24.2.1~rc2-0ubuntu1
4:24.2.2~rc2-0ubuntu1
4:24.2.2-0ubuntu1
4:24.2.3-0ubuntu0.24.04.1
4:24.2.3-0ubuntu0.24.04.2
4:24.2.4-0ubuntu0.24.04.1
4:24.2.4-0ubuntu0.24.04.2
4:24.2.5-0ubuntu0.24.04.1
4:24.2.5-0ubuntu0.24.04.2
4:24.2.6-0ubuntu0.24.04.1
4:24.2.7-0ubuntu0.24.04.1
4:24.2.7-0ubuntu0.24.04.2

Ecosystem specific

{
    "ubuntu_priority": "low",
    "priority_reason": "Denial of service via resource exhaustion in a desktop application"
}