Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2020:2283-1

Опубликовано: 20 авг. 2020
Источник: suse-cvrf

Описание

Security update for libreoffice

This update for libreoffice fixes the following issues:

  • Update to 6.4.5.2:
    • Various fixes all around
  • Remove mime-info and application-registry dirs bsc#1062631
  • Fix bsc#1172053 - LO-L3: Image disappears during roundtrip 365->Impress->365
    • bsc1172053.diff
  • Fix bsc#1172189 - LO-L3: Impress crashes midway opening a PPTX document
    • bsc1172189.diff
  • Fix bsc#1157627 - LO-L3: Some XML-created shapes simply lost upon PPTX import (= earth loses countries)
    • bsc1157627.diff
  • Fix bsc#1146025 - LO-L3: Colored textboxes in PPTX look very odd (SmartArt)
  • Fix bsc#1165849 - LO-L3: Shadow size for rectangle is only a fraction of Office 365
    • bsc1165849-1.diff
    • bsc1165849-2.diff
    • bsc1165849-3.diff

Список пакетов

SUSE Linux Enterprise Software Development Kit 12 SP5
libreoffice-sdk-6.4.5.2-43.68.1
SUSE Linux Enterprise Workstation Extension 12 SP5
libreoffice-6.4.5.2-43.68.1
libreoffice-base-6.4.5.2-43.68.1
libreoffice-base-drivers-postgresql-6.4.5.2-43.68.1
libreoffice-branding-upstream-6.4.5.2-43.68.1
libreoffice-calc-6.4.5.2-43.68.1
libreoffice-calc-extensions-6.4.5.2-43.68.1
libreoffice-draw-6.4.5.2-43.68.1
libreoffice-filters-optional-6.4.5.2-43.68.1
libreoffice-gnome-6.4.5.2-43.68.1
libreoffice-icon-themes-6.4.5.2-43.68.1
libreoffice-impress-6.4.5.2-43.68.1
libreoffice-l10n-af-6.4.5.2-43.68.1
libreoffice-l10n-ar-6.4.5.2-43.68.1
libreoffice-l10n-bg-6.4.5.2-43.68.1
libreoffice-l10n-ca-6.4.5.2-43.68.1
libreoffice-l10n-cs-6.4.5.2-43.68.1
libreoffice-l10n-da-6.4.5.2-43.68.1
libreoffice-l10n-de-6.4.5.2-43.68.1
libreoffice-l10n-en-6.4.5.2-43.68.1
libreoffice-l10n-es-6.4.5.2-43.68.1
libreoffice-l10n-fi-6.4.5.2-43.68.1
libreoffice-l10n-fr-6.4.5.2-43.68.1
libreoffice-l10n-gu-6.4.5.2-43.68.1
libreoffice-l10n-hi-6.4.5.2-43.68.1
libreoffice-l10n-hr-6.4.5.2-43.68.1
libreoffice-l10n-hu-6.4.5.2-43.68.1
libreoffice-l10n-it-6.4.5.2-43.68.1
libreoffice-l10n-ja-6.4.5.2-43.68.1
libreoffice-l10n-ko-6.4.5.2-43.68.1
libreoffice-l10n-lt-6.4.5.2-43.68.1
libreoffice-l10n-nb-6.4.5.2-43.68.1
libreoffice-l10n-nl-6.4.5.2-43.68.1
libreoffice-l10n-nn-6.4.5.2-43.68.1
libreoffice-l10n-pl-6.4.5.2-43.68.1
libreoffice-l10n-pt_BR-6.4.5.2-43.68.1
libreoffice-l10n-pt_PT-6.4.5.2-43.68.1
libreoffice-l10n-ro-6.4.5.2-43.68.1
libreoffice-l10n-ru-6.4.5.2-43.68.1
libreoffice-l10n-sk-6.4.5.2-43.68.1
libreoffice-l10n-sv-6.4.5.2-43.68.1
libreoffice-l10n-uk-6.4.5.2-43.68.1
libreoffice-l10n-xh-6.4.5.2-43.68.1
libreoffice-l10n-zh_CN-6.4.5.2-43.68.1
libreoffice-l10n-zh_TW-6.4.5.2-43.68.1
libreoffice-l10n-zu-6.4.5.2-43.68.1
libreoffice-librelogo-6.4.5.2-43.68.1
libreoffice-mailmerge-6.4.5.2-43.68.1
libreoffice-math-6.4.5.2-43.68.1
libreoffice-officebean-6.4.5.2-43.68.1
libreoffice-pyuno-6.4.5.2-43.68.1
libreoffice-writer-6.4.5.2-43.68.1
libreoffice-writer-extensions-6.4.5.2-43.68.1

Описание

LibreOffice has a 'stealth mode' in which only documents from locations deemed 'trusted' are allowed to retrieve remote resources. This mode is not the default mode, but can be enabled by users who want to disable LibreOffice's ability to include remote resources within a document. A flaw existed where remote graphic links loaded from docx documents were omitted from this protection prior to version 6.4.4. This issue affects: The Document Foundation LibreOffice versions prior to 6.4.4.


Затронутые продукты
SUSE Linux Enterprise Software Development Kit 12 SP5:libreoffice-sdk-6.4.5.2-43.68.1
SUSE Linux Enterprise Workstation Extension 12 SP5:libreoffice-6.4.5.2-43.68.1
SUSE Linux Enterprise Workstation Extension 12 SP5:libreoffice-base-6.4.5.2-43.68.1
SUSE Linux Enterprise Workstation Extension 12 SP5:libreoffice-base-drivers-postgresql-6.4.5.2-43.68.1

Ссылки

Описание

ODF documents can contain forms to be filled out by the user. Similar to HTML forms, the contained form data can be submitted to a URI, for example, to an external web server. To create submittable forms, ODF implements the XForms W3C standard, which allows data to be submitted without the need for macros or other active scripting Prior to version 6.4.4 LibreOffice allowed forms to be submitted to any URI, including file: URIs, enabling form submissions to overwrite local files. User-interaction is required to submit the form, but to avoid the possibility of malicious documents engineered to maximize the possibility of inadvertent user submission this feature has now been limited to http[s] URIs, removing the possibility to overwrite local files. This issue affects: The Document Foundation LibreOffice versions prior to 6.4.4.


Затронутые продукты
SUSE Linux Enterprise Software Development Kit 12 SP5:libreoffice-sdk-6.4.5.2-43.68.1
SUSE Linux Enterprise Workstation Extension 12 SP5:libreoffice-6.4.5.2-43.68.1
SUSE Linux Enterprise Workstation Extension 12 SP5:libreoffice-base-6.4.5.2-43.68.1
SUSE Linux Enterprise Workstation Extension 12 SP5:libreoffice-base-drivers-postgresql-6.4.5.2-43.68.1

Ссылки