Описание
Security update for libreoffice
This update for libreoffice fixes the following issues:
- Update to 6.4.5.2:
- Various fixes all around
- Remove mime-info and application-registry dirs bsc#1062631
- Fix bsc#1172053 - LO-L3: Image disappears during roundtrip 365->Impress->365
- bsc1172053.diff
- Fix bsc#1172189 - LO-L3: Impress crashes midway opening a PPTX document
- bsc1172189.diff
- Fix bsc#1157627 - LO-L3: Some XML-created shapes simply lost upon PPTX import (= earth loses countries)
- bsc1157627.diff
- Fix bsc#1146025 - LO-L3: Colored textboxes in PPTX look very odd (SmartArt)
- Fix bsc#1165849 - LO-L3: Shadow size for rectangle is only a fraction of Office 365
- bsc1165849-1.diff
- bsc1165849-2.diff
- bsc1165849-3.diff
Список пакетов
SUSE Linux Enterprise Software Development Kit 12 SP5
SUSE Linux Enterprise Workstation Extension 12 SP5
Ссылки
- Link for SUSE-SU-2020:2283-1
- E-Mail link for SUSE-SU-2020:2283-1
- SUSE Security Ratings
- SUSE Bug 1062631
- SUSE Bug 1146025
- SUSE Bug 1157627
- SUSE Bug 1165849
- SUSE Bug 1172053
- SUSE Bug 1172189
- SUSE Bug 1172795
- SUSE Bug 1172796
- SUSE CVE CVE-2020-12802 page
- SUSE CVE CVE-2020-12803 page
Описание
LibreOffice has a 'stealth mode' in which only documents from locations deemed 'trusted' are allowed to retrieve remote resources. This mode is not the default mode, but can be enabled by users who want to disable LibreOffice's ability to include remote resources within a document. A flaw existed where remote graphic links loaded from docx documents were omitted from this protection prior to version 6.4.4. This issue affects: The Document Foundation LibreOffice versions prior to 6.4.4.
Затронутые продукты
Ссылки
- CVE-2020-12802
- SUSE Bug 1172796
Описание
ODF documents can contain forms to be filled out by the user. Similar to HTML forms, the contained form data can be submitted to a URI, for example, to an external web server. To create submittable forms, ODF implements the XForms W3C standard, which allows data to be submitted without the need for macros or other active scripting Prior to version 6.4.4 LibreOffice allowed forms to be submitted to any URI, including file: URIs, enabling form submissions to overwrite local files. User-interaction is required to submit the form, but to avoid the possibility of malicious documents engineered to maximize the possibility of inadvertent user submission this feature has now been limited to http[s] URIs, removing the possibility to overwrite local files. This issue affects: The Document Foundation LibreOffice versions prior to 6.4.4.
Затронутые продукты
Ссылки
- CVE-2020-12803
- SUSE Bug 1172795