ALT-BU-2016-3145-1
Branch c7 update bulletin.
Package LibreOffice4 updated to version 4.2-alt2.M70C.4 for branch c7 in task 172232.
Closed vulnerabilities
BDU:2015-12098
Уязвимость операционных систем Debian GNU/Linux, Ubuntu, пакетов офисных программ LibreOffice и Apache OpenOffice, позволяющая нарушителю получить доступ к защищаемой информации
BDU:2015-12101
Уязвимость операционных систем Debian GNU/Linux, Ubuntu, пакетов офисных программ LibreOffice и Apache OpenOffice, позволяющая нарушителю вызвать отказ в обслуживании или выполнить произвольный код
BDU:2015-12102
Уязвимость операционных систем Debian GNU/Linux, Ubuntu, пакетов офисных программ LibreOffice и Apache OpenOffice, позволяющая нарушителю вызвать отказ в обслуживании или выполнить произвольный код
BDU:2015-12103
Уязвимость операционных систем Debian GNU/Linux, Ubuntu, пакетов офисных программ LibreOffice и Apache OpenOffice, позволяющая нарушителю вызвать отказ в обслуживании или выполнить произвольный код
BDU:2016-00439
Уязвимость пакета офисных программ LibreOffice, позволяющая нарушителю вызвать отказ в обслуживании или оказать другое воздействие
BDU:2016-00440
Уязвимость пакета офисных программ LibreOffice, позволяющая нарушителю вызвать отказ в обслуживании или оказать другое воздействие
BDU:2016-01694
Уязвимость пакета офисных программ LibreOffice, позволяющая нарушителю выполнить произвольный код
BDU:2020-02956
Уязвимость фильтра HWP пакета офисных программ LibreOffice, позволяющая нарушителю получить несанкционированный доступ к конфиденциальным данным, вызвать отказ в обслуживании или оказать воздействие на целостность данных
Modified: 2024-11-21
CVE-2015-1774
The HWP filter in LibreOffice before 4.3.7 and 4.4.x before 4.4.2 and Apache OpenOffice before 4.1.2 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted HWP document, which triggers an out-of-bounds write.
- FEDORA-2015-7022
- FEDORA-2015-7022
- FEDORA-2015-7213
- FEDORA-2015-7213
- openSUSE-SU-2015:0859
- openSUSE-SU-2015:0859
- RHSA-2015:1458
- RHSA-2015:1458
- DSA-3236
- DSA-3236
- http://www.openoffice.org/security/cves/CVE-2015-1774.html
- http://www.openoffice.org/security/cves/CVE-2015-1774.html
- 74338
- 74338
- 1032205
- 1032205
- 1032206
- 1032206
- USN-2578-1
- USN-2578-1
- GLSA-201603-05
- GLSA-201603-05
- https://www.libreoffice.org/about-us/security/advisories/cve-2015-1774/
- https://www.libreoffice.org/about-us/security/advisories/cve-2015-1774/
- 20150427 Multiple Vendor LibreOffice "HWPFILTER" Out Of Bounds Access Vulnerability
- 20150427 Multiple Vendor LibreOffice "HWPFILTER" Out Of Bounds Access Vulnerability
Modified: 2024-11-21
CVE-2015-4551
LibreOffice before 4.4.5 and Apache OpenOffice before 4.1.2 uses the stored LinkUpdateMode configuration information in OpenDocument Format files and templates when handling links, which might allow remote attackers to obtain sensitive information via a crafted document, which embeds data from local files into (1) Calc or (2) Writer.
- RHSA-2015:2619
- RHSA-2015:2619
- DSA-3394
- DSA-3394
- http://www.libreoffice.org/about-us/security/advisories/cve-2015-4551/
- http://www.libreoffice.org/about-us/security/advisories/cve-2015-4551/
- http://www.openoffice.org/security/cves/CVE-2015-4551.html
- http://www.openoffice.org/security/cves/CVE-2015-4551.html
- http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.html
- http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.html
- 77486
- 77486
- 1034085
- 1034085
- 1034091
- 1034091
- USN-2793-1
- USN-2793-1
- GLSA-201603-05
- GLSA-201603-05
- GLSA-201611-03
- GLSA-201611-03
Modified: 2024-11-21
CVE-2015-5212
Integer underflow in LibreOffice before 4.4.5 and Apache OpenOffice before 4.1.2, when the configuration setting "Load printer settings with the document" is enabled, allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via crafted PrinterSetup data in an ODF document.
- RHSA-2015:2619
- RHSA-2015:2619
- DSA-3394
- DSA-3394
- http://www.libreoffice.org/about-us/security/advisories/cve-2015-5212/
- http://www.libreoffice.org/about-us/security/advisories/cve-2015-5212/
- http://www.openoffice.org/security/cves/CVE-2015-5212.html
- http://www.openoffice.org/security/cves/CVE-2015-5212.html
- http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.html
- http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.html
- 77486
- 77486
- 1034085
- 1034085
- 1034091
- 1034091
- USN-2793-1
- USN-2793-1
- GLSA-201603-05
- GLSA-201603-05
- GLSA-201611-03
- GLSA-201611-03
Modified: 2024-11-21
CVE-2015-5213
Integer overflow in LibreOffice before 4.4.5 and Apache OpenOffice before 4.1.2 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via a long DOC file, which triggers a buffer overflow.
- RHSA-2015:2619
- RHSA-2015:2619
- DSA-3394
- DSA-3394
- http://www.libreoffice.org/about-us/security/advisories/cve-2015-5213/
- http://www.libreoffice.org/about-us/security/advisories/cve-2015-5213/
- http://www.openoffice.org/security/cves/CVE-2015-5213.html
- http://www.openoffice.org/security/cves/CVE-2015-5213.html
- http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.html
- http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.html
- 77486
- 77486
- 1034085
- 1034085
- 1034091
- 1034091
- USN-2793-1
- USN-2793-1
- GLSA-201603-05
- GLSA-201603-05
- GLSA-201611-03
- GLSA-201611-03
Modified: 2024-11-21
CVE-2015-5214
LibreOffice before 4.4.6 and 5.x before 5.0.1 and Apache OpenOffice before 4.1.2 allows remote attackers to cause a denial of service (memory corruption and application crash) or execute arbitrary code via an index to a non-existent bookmark in a DOC file.
- RHSA-2015:2619
- RHSA-2015:2619
- DSA-3394
- DSA-3394
- http://www.libreoffice.org/about-us/security/advisories/cve-2015-5214/
- http://www.libreoffice.org/about-us/security/advisories/cve-2015-5214/
- http://www.openoffice.org/security/cves/CVE-2015-5214.html
- http://www.openoffice.org/security/cves/CVE-2015-5214.html
- http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.html
- http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.html
- 77486
- 77486
- 1034086
- 1034086
- 1034091
- 1034091
- USN-2793-1
- USN-2793-1
- GLSA-201603-05
- GLSA-201603-05
- GLSA-201611-03
- GLSA-201611-03
Modified: 2024-11-21
CVE-2016-0794
The lwp filter in LibreOffice before 5.0.4 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a crafted LotusWordPro (lwp) document.
- FEDORA-2016-962c0d156d
- FEDORA-2016-962c0d156d
- openSUSE-SU-2016:1415
- openSUSE-SU-2016:1415
- openSUSE-SU-2016:1805
- openSUSE-SU-2016:1805
- RHSA-2016:2579
- RHSA-2016:2579
- DSA-3482
- DSA-3482
- 1035022
- 1035022
- USN-2899-1
- USN-2899-1
- https://www.libreoffice.org/about-us/security/advisories/cve-2016-0794/
- https://www.libreoffice.org/about-us/security/advisories/cve-2016-0794/
- 20160217 Multiple Vendor LibreOffice Writer Lotus Word Pro 'ReadRootData' Buffer Overflow Vulnerability
- 20160217 Multiple Vendor LibreOffice Writer Lotus Word Pro 'ReadRootData' Buffer Overflow Vulnerability
- 20160217 Multiple Vendor LibreOffice Writer Lotus Word Pro TabRack Buffer Overflow Vulnerability
- 20160217 Multiple Vendor LibreOffice Writer Lotus Word Pro TabRack Buffer Overflow Vulnerability
- 20160217 Multiple Vendor LibreOffice Writer Lotus Word Pro Bullet Buffer Overflow Vulnerability
- 20160217 Multiple Vendor LibreOffice Writer Lotus Word Pro Bullet Buffer Overflow Vulnerability
Modified: 2024-11-21
CVE-2016-0795
LibreOffice before 5.0.5 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a crafted LwpTocSuperLayout record in a LotusWordPro (lwp) document.
- FEDORA-2016-962c0d156d
- FEDORA-2016-962c0d156d
- openSUSE-SU-2016:1415
- openSUSE-SU-2016:1415
- openSUSE-SU-2016:1805
- openSUSE-SU-2016:1805
- RHSA-2016:2579
- RHSA-2016:2579
- DSA-3482
- DSA-3482
- 1035022
- 1035022
- USN-2899-1
- USN-2899-1
- https://www.libreoffice.org/about-us/security/advisories/cve-2016-0795/
- https://www.libreoffice.org/about-us/security/advisories/cve-2016-0795/
- 20160217 Multiple Vendor LibreOffice Writer Lotus Word Pro 'TocSuperLayout' Buffer Overflow Vulnerability
- 20160217 Multiple Vendor LibreOffice Writer Lotus Word Pro 'TocSuperLayout' Buffer Overflow Vulnerability
Modified: 2024-11-21
CVE-2016-4324
Use-after-free vulnerability in LibreOffice before 5.1.4 allows remote attackers to execute arbitrary code via a crafted RTF file, related to stylesheet and superscript tokens.
- DSA-3608
- DSA-3608
- http://www.libreoffice.org/about-us/security/advisories/cve-2016-4324/
- http://www.libreoffice.org/about-us/security/advisories/cve-2016-4324/
- 91499
- 91499
- 1036209
- 1036209
- http://www.talosintelligence.com/reports/TALOS-2016-0126/
- http://www.talosintelligence.com/reports/TALOS-2016-0126/
- USN-3022-1
- USN-3022-1
- GLSA-201611-03
- GLSA-201611-03