Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2016:2472-1

Опубликовано: 06 окт. 2016
Источник: suse-cvrf

Описание

Security update for libreoffice

LibreOffice was updated to version 5.1.5.2, bringing enhancements and bug fixes.

  • CVE-2016-4324: Parsing the Rich Text Format character style index was insufficiently checked for validity. Documents could be constructed which dereference an iterator to the first entry of an empty STL container. (bsc#987553)
  • Don't use 'nullable' for introspection, as it isn't available on SLE 12's version of gobject-introspection. This prevents a segmentation fault in gnome-documents. (bsc#1000102)

Список пакетов

SUSE Linux Enterprise Desktop 12 SP1
libreoffice-5.1.5.2-29.4
libreoffice-base-5.1.5.2-29.4
libreoffice-base-drivers-mysql-5.1.5.2-29.4
libreoffice-base-drivers-postgresql-5.1.5.2-29.4
libreoffice-calc-5.1.5.2-29.4
libreoffice-calc-extensions-5.1.5.2-29.4
libreoffice-draw-5.1.5.2-29.4
libreoffice-filters-optional-5.1.5.2-29.4
libreoffice-gnome-5.1.5.2-29.4
libreoffice-icon-theme-galaxy-5.1.5.2-29.4
libreoffice-icon-theme-tango-5.1.5.2-29.4
libreoffice-impress-5.1.5.2-29.4
libreoffice-l10n-af-5.1.5.2-29.4
libreoffice-l10n-ar-5.1.5.2-29.4
libreoffice-l10n-ca-5.1.5.2-29.4
libreoffice-l10n-cs-5.1.5.2-29.4
libreoffice-l10n-da-5.1.5.2-29.4
libreoffice-l10n-de-5.1.5.2-29.4
libreoffice-l10n-en-5.1.5.2-29.4
libreoffice-l10n-es-5.1.5.2-29.4
libreoffice-l10n-fi-5.1.5.2-29.4
libreoffice-l10n-fr-5.1.5.2-29.4
libreoffice-l10n-gu-5.1.5.2-29.4
libreoffice-l10n-hi-5.1.5.2-29.4
libreoffice-l10n-hu-5.1.5.2-29.4
libreoffice-l10n-it-5.1.5.2-29.4
libreoffice-l10n-ja-5.1.5.2-29.4
libreoffice-l10n-ko-5.1.5.2-29.4
libreoffice-l10n-nb-5.1.5.2-29.4
libreoffice-l10n-nl-5.1.5.2-29.4
libreoffice-l10n-nn-5.1.5.2-29.4
libreoffice-l10n-pl-5.1.5.2-29.4
libreoffice-l10n-pt-BR-5.1.5.2-29.4
libreoffice-l10n-pt-PT-5.1.5.2-29.4
libreoffice-l10n-ru-5.1.5.2-29.4
libreoffice-l10n-sk-5.1.5.2-29.4
libreoffice-l10n-sv-5.1.5.2-29.4
libreoffice-l10n-xh-5.1.5.2-29.4
libreoffice-l10n-zh-Hans-5.1.5.2-29.4
libreoffice-l10n-zh-Hant-5.1.5.2-29.4
libreoffice-l10n-zu-5.1.5.2-29.4
libreoffice-mailmerge-5.1.5.2-29.4
libreoffice-math-5.1.5.2-29.4
libreoffice-officebean-5.1.5.2-29.4
libreoffice-pyuno-5.1.5.2-29.4
libreoffice-writer-5.1.5.2-29.4
libreoffice-writer-extensions-5.1.5.2-29.4
SUSE Linux Enterprise Workstation Extension 12 SP1
libreoffice-5.1.5.2-29.4
libreoffice-base-5.1.5.2-29.4
libreoffice-base-drivers-mysql-5.1.5.2-29.4
libreoffice-base-drivers-postgresql-5.1.5.2-29.4
libreoffice-calc-5.1.5.2-29.4
libreoffice-calc-extensions-5.1.5.2-29.4
libreoffice-draw-5.1.5.2-29.4
libreoffice-filters-optional-5.1.5.2-29.4
libreoffice-gnome-5.1.5.2-29.4
libreoffice-icon-theme-galaxy-5.1.5.2-29.4
libreoffice-icon-theme-tango-5.1.5.2-29.4
libreoffice-impress-5.1.5.2-29.4
libreoffice-l10n-af-5.1.5.2-29.4
libreoffice-l10n-ar-5.1.5.2-29.4
libreoffice-l10n-ca-5.1.5.2-29.4
libreoffice-l10n-cs-5.1.5.2-29.4
libreoffice-l10n-da-5.1.5.2-29.4
libreoffice-l10n-de-5.1.5.2-29.4
libreoffice-l10n-en-5.1.5.2-29.4
libreoffice-l10n-es-5.1.5.2-29.4
libreoffice-l10n-fi-5.1.5.2-29.4
libreoffice-l10n-fr-5.1.5.2-29.4
libreoffice-l10n-gu-5.1.5.2-29.4
libreoffice-l10n-hi-5.1.5.2-29.4
libreoffice-l10n-hu-5.1.5.2-29.4
libreoffice-l10n-it-5.1.5.2-29.4
libreoffice-l10n-ja-5.1.5.2-29.4
libreoffice-l10n-ko-5.1.5.2-29.4
libreoffice-l10n-nb-5.1.5.2-29.4
libreoffice-l10n-nl-5.1.5.2-29.4
libreoffice-l10n-nn-5.1.5.2-29.4
libreoffice-l10n-pl-5.1.5.2-29.4
libreoffice-l10n-pt-BR-5.1.5.2-29.4
libreoffice-l10n-pt-PT-5.1.5.2-29.4
libreoffice-l10n-ru-5.1.5.2-29.4
libreoffice-l10n-sk-5.1.5.2-29.4
libreoffice-l10n-sv-5.1.5.2-29.4
libreoffice-l10n-xh-5.1.5.2-29.4
libreoffice-l10n-zh-Hans-5.1.5.2-29.4
libreoffice-l10n-zh-Hant-5.1.5.2-29.4
libreoffice-l10n-zu-5.1.5.2-29.4
libreoffice-mailmerge-5.1.5.2-29.4
libreoffice-math-5.1.5.2-29.4
libreoffice-officebean-5.1.5.2-29.4
libreoffice-pyuno-5.1.5.2-29.4
libreoffice-writer-5.1.5.2-29.4
libreoffice-writer-extensions-5.1.5.2-29.4

Описание

Use-after-free vulnerability in LibreOffice before 5.1.4 allows remote attackers to execute arbitrary code via a crafted RTF file, related to stylesheet and superscript tokens.


Затронутые продукты
SUSE Linux Enterprise Desktop 12 SP1:libreoffice-5.1.5.2-29.4
SUSE Linux Enterprise Desktop 12 SP1:libreoffice-base-5.1.5.2-29.4
SUSE Linux Enterprise Desktop 12 SP1:libreoffice-base-drivers-mysql-5.1.5.2-29.4
SUSE Linux Enterprise Desktop 12 SP1:libreoffice-base-drivers-postgresql-5.1.5.2-29.4

Ссылки