Описание
Security update for libreoffice
LibreOffice was updated to version 5.1.5.2, bringing enhancements and bug fixes.
- CVE-2016-4324: Parsing the Rich Text Format character style index was insufficiently checked for validity. Documents could be constructed which dereference an iterator to the first entry of an empty STL container. (bsc#987553)
- Don't use 'nullable' for introspection, as it isn't available on SLE 12's version of gobject-introspection. This prevents a segmentation fault in gnome-documents. (bsc#1000102)
Список пакетов
SUSE Linux Enterprise Desktop 12 SP1
libreoffice-5.1.5.2-29.4
libreoffice-base-5.1.5.2-29.4
libreoffice-base-drivers-mysql-5.1.5.2-29.4
libreoffice-base-drivers-postgresql-5.1.5.2-29.4
libreoffice-calc-5.1.5.2-29.4
libreoffice-calc-extensions-5.1.5.2-29.4
libreoffice-draw-5.1.5.2-29.4
libreoffice-filters-optional-5.1.5.2-29.4
libreoffice-gnome-5.1.5.2-29.4
libreoffice-icon-theme-galaxy-5.1.5.2-29.4
libreoffice-icon-theme-tango-5.1.5.2-29.4
libreoffice-impress-5.1.5.2-29.4
libreoffice-l10n-af-5.1.5.2-29.4
libreoffice-l10n-ar-5.1.5.2-29.4
libreoffice-l10n-ca-5.1.5.2-29.4
libreoffice-l10n-cs-5.1.5.2-29.4
libreoffice-l10n-da-5.1.5.2-29.4
libreoffice-l10n-de-5.1.5.2-29.4
libreoffice-l10n-en-5.1.5.2-29.4
libreoffice-l10n-es-5.1.5.2-29.4
libreoffice-l10n-fi-5.1.5.2-29.4
libreoffice-l10n-fr-5.1.5.2-29.4
libreoffice-l10n-gu-5.1.5.2-29.4
libreoffice-l10n-hi-5.1.5.2-29.4
libreoffice-l10n-hu-5.1.5.2-29.4
libreoffice-l10n-it-5.1.5.2-29.4
libreoffice-l10n-ja-5.1.5.2-29.4
libreoffice-l10n-ko-5.1.5.2-29.4
libreoffice-l10n-nb-5.1.5.2-29.4
libreoffice-l10n-nl-5.1.5.2-29.4
libreoffice-l10n-nn-5.1.5.2-29.4
libreoffice-l10n-pl-5.1.5.2-29.4
libreoffice-l10n-pt-BR-5.1.5.2-29.4
libreoffice-l10n-pt-PT-5.1.5.2-29.4
libreoffice-l10n-ru-5.1.5.2-29.4
libreoffice-l10n-sk-5.1.5.2-29.4
libreoffice-l10n-sv-5.1.5.2-29.4
libreoffice-l10n-xh-5.1.5.2-29.4
libreoffice-l10n-zh-Hans-5.1.5.2-29.4
libreoffice-l10n-zh-Hant-5.1.5.2-29.4
libreoffice-l10n-zu-5.1.5.2-29.4
libreoffice-mailmerge-5.1.5.2-29.4
libreoffice-math-5.1.5.2-29.4
libreoffice-officebean-5.1.5.2-29.4
libreoffice-pyuno-5.1.5.2-29.4
libreoffice-writer-5.1.5.2-29.4
libreoffice-writer-extensions-5.1.5.2-29.4
SUSE Linux Enterprise Workstation Extension 12 SP1
libreoffice-5.1.5.2-29.4
libreoffice-base-5.1.5.2-29.4
libreoffice-base-drivers-mysql-5.1.5.2-29.4
libreoffice-base-drivers-postgresql-5.1.5.2-29.4
libreoffice-calc-5.1.5.2-29.4
libreoffice-calc-extensions-5.1.5.2-29.4
libreoffice-draw-5.1.5.2-29.4
libreoffice-filters-optional-5.1.5.2-29.4
libreoffice-gnome-5.1.5.2-29.4
libreoffice-icon-theme-galaxy-5.1.5.2-29.4
libreoffice-icon-theme-tango-5.1.5.2-29.4
libreoffice-impress-5.1.5.2-29.4
libreoffice-l10n-af-5.1.5.2-29.4
libreoffice-l10n-ar-5.1.5.2-29.4
libreoffice-l10n-ca-5.1.5.2-29.4
libreoffice-l10n-cs-5.1.5.2-29.4
libreoffice-l10n-da-5.1.5.2-29.4
libreoffice-l10n-de-5.1.5.2-29.4
libreoffice-l10n-en-5.1.5.2-29.4
libreoffice-l10n-es-5.1.5.2-29.4
libreoffice-l10n-fi-5.1.5.2-29.4
libreoffice-l10n-fr-5.1.5.2-29.4
libreoffice-l10n-gu-5.1.5.2-29.4
libreoffice-l10n-hi-5.1.5.2-29.4
libreoffice-l10n-hu-5.1.5.2-29.4
libreoffice-l10n-it-5.1.5.2-29.4
libreoffice-l10n-ja-5.1.5.2-29.4
libreoffice-l10n-ko-5.1.5.2-29.4
libreoffice-l10n-nb-5.1.5.2-29.4
libreoffice-l10n-nl-5.1.5.2-29.4
libreoffice-l10n-nn-5.1.5.2-29.4
libreoffice-l10n-pl-5.1.5.2-29.4
libreoffice-l10n-pt-BR-5.1.5.2-29.4
libreoffice-l10n-pt-PT-5.1.5.2-29.4
libreoffice-l10n-ru-5.1.5.2-29.4
libreoffice-l10n-sk-5.1.5.2-29.4
libreoffice-l10n-sv-5.1.5.2-29.4
libreoffice-l10n-xh-5.1.5.2-29.4
libreoffice-l10n-zh-Hans-5.1.5.2-29.4
libreoffice-l10n-zh-Hant-5.1.5.2-29.4
libreoffice-l10n-zu-5.1.5.2-29.4
libreoffice-mailmerge-5.1.5.2-29.4
libreoffice-math-5.1.5.2-29.4
libreoffice-officebean-5.1.5.2-29.4
libreoffice-pyuno-5.1.5.2-29.4
libreoffice-writer-5.1.5.2-29.4
libreoffice-writer-extensions-5.1.5.2-29.4
Ссылки
- Link for SUSE-SU-2016:2472-1
- E-Mail link for SUSE-SU-2016:2472-1
- SUSE Security Ratings
- SUSE Bug 1000102
- SUSE Bug 987553
- SUSE CVE CVE-2016-4324 page
Описание
Use-after-free vulnerability in LibreOffice before 5.1.4 allows remote attackers to execute arbitrary code via a crafted RTF file, related to stylesheet and superscript tokens.
Затронутые продукты
SUSE Linux Enterprise Desktop 12 SP1:libreoffice-5.1.5.2-29.4
SUSE Linux Enterprise Desktop 12 SP1:libreoffice-base-5.1.5.2-29.4
SUSE Linux Enterprise Desktop 12 SP1:libreoffice-base-drivers-mysql-5.1.5.2-29.4
SUSE Linux Enterprise Desktop 12 SP1:libreoffice-base-drivers-postgresql-5.1.5.2-29.4
Ссылки
- CVE-2016-4324
- SUSE Bug 987553