Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2023:4648-1

Опубликовано: 06 дек. 2023
Источник: suse-cvrf

Описание

Security update for libreoffice

This update for fixes the following issues:

libreoffice was updated rom 7.5.4.1 to 7.6.2.1 (jsc#PED-6799, jsc#PED-6800):

frozen was implemented:

  • New Libreoffice package dependency

libixion was updated to version 0.18.1:

  • Updated to 0.18.1:

    • Fixed a 32-bit Linux build issue as discovered on Debian, due to a clash on two 32-bit unsigned integer types being used with std::variant.
  • Updated to 0.18.0:

    • Removed the formula_model_access interface from model_context, and switched to using model_context directly everywhere.
    • Revised formula_tokens_t type to remove use of std::unique_ptr for each formula_token instance. This should improve memory locality when iterating through an array of formula token values. A similar change has also been made to lexer_tokens_t and lexer_token types.
    • Added 41 built-in functions
    • Added support for multi-sheet references in Excel A1 and Excel R1C1 grammers.

liborcus was updated to version 0.18.1:

  • Updated to 0.18.1:

    • sax parser:

      • added support for optionally skipping multiple BOM's in the beginning of XML stream. This affects all XML-based file format filters such as xls-xml (aka Excel 2003 XML).
    • xml-map:

      • fixed a bug where an XML document consisting of simple single-column records were not properly converted to sheet data
    • xls-xml:

      • fixed a bug where the filter would always pass border color even when it was not set
    • buildsystem:

      • added new configure switches --without-benchmark and --without-doc-example to optinally skip building of these two directories

mdds-2_1 was implemented:

  • New Libreoffice package dependency

Список пакетов

SUSE Linux Enterprise Software Development Kit 12 SP5
frozen-devel-1.1.1-8.3.3
libetonyek-0_1-1-0.1.10-10.11.2
libetonyek-devel-0.1.10-10.11.2
libetonyek-devel-doc-0.1.10-10.11.2
libixion-0_18-0-0.18.1-21.3.3
libixion-devel-0.18.1-21.3.3
liborcus-0_18-0-0.18.1-18.3.3
liborcus-devel-0.18.1-18.3.3
libreoffice-sdk-7.6.2.1-48.47.6
mdds-2_1-devel-2.1.1-8.3.3
SUSE Linux Enterprise Workstation Extension 12 SP5
libetonyek-0_1-1-0.1.10-10.11.2
libixion-0_18-0-0.18.1-21.3.3
liborcus-0_18-0-0.18.1-18.3.3
libreoffice-7.6.2.1-48.47.6
libreoffice-base-7.6.2.1-48.47.6
libreoffice-base-drivers-postgresql-7.6.2.1-48.47.6
libreoffice-branding-upstream-7.6.2.1-48.47.6
libreoffice-calc-7.6.2.1-48.47.6
libreoffice-calc-extensions-7.6.2.1-48.47.6
libreoffice-draw-7.6.2.1-48.47.6
libreoffice-filters-optional-7.6.2.1-48.47.6
libreoffice-gnome-7.6.2.1-48.47.6
libreoffice-gtk3-7.6.2.1-48.47.6
libreoffice-icon-themes-7.6.2.1-48.47.6
libreoffice-impress-7.6.2.1-48.47.6
libreoffice-l10n-af-7.6.2.1-48.47.6
libreoffice-l10n-ar-7.6.2.1-48.47.6
libreoffice-l10n-bg-7.6.2.1-48.47.6
libreoffice-l10n-ca-7.6.2.1-48.47.6
libreoffice-l10n-cs-7.6.2.1-48.47.6
libreoffice-l10n-da-7.6.2.1-48.47.6
libreoffice-l10n-de-7.6.2.1-48.47.6
libreoffice-l10n-en-7.6.2.1-48.47.6
libreoffice-l10n-es-7.6.2.1-48.47.6
libreoffice-l10n-fi-7.6.2.1-48.47.6
libreoffice-l10n-fr-7.6.2.1-48.47.6
libreoffice-l10n-gu-7.6.2.1-48.47.6
libreoffice-l10n-hi-7.6.2.1-48.47.6
libreoffice-l10n-hr-7.6.2.1-48.47.6
libreoffice-l10n-hu-7.6.2.1-48.47.6
libreoffice-l10n-it-7.6.2.1-48.47.6
libreoffice-l10n-ja-7.6.2.1-48.47.6
libreoffice-l10n-ko-7.6.2.1-48.47.6
libreoffice-l10n-lt-7.6.2.1-48.47.6
libreoffice-l10n-nb-7.6.2.1-48.47.6
libreoffice-l10n-nl-7.6.2.1-48.47.6
libreoffice-l10n-nn-7.6.2.1-48.47.6
libreoffice-l10n-pl-7.6.2.1-48.47.6
libreoffice-l10n-pt_BR-7.6.2.1-48.47.6
libreoffice-l10n-pt_PT-7.6.2.1-48.47.6
libreoffice-l10n-ro-7.6.2.1-48.47.6
libreoffice-l10n-ru-7.6.2.1-48.47.6
libreoffice-l10n-sk-7.6.2.1-48.47.6
libreoffice-l10n-sv-7.6.2.1-48.47.6
libreoffice-l10n-uk-7.6.2.1-48.47.6
libreoffice-l10n-xh-7.6.2.1-48.47.6
libreoffice-l10n-zh_CN-7.6.2.1-48.47.6
libreoffice-l10n-zh_TW-7.6.2.1-48.47.6
libreoffice-l10n-zu-7.6.2.1-48.47.6
libreoffice-librelogo-7.6.2.1-48.47.6
libreoffice-mailmerge-7.6.2.1-48.47.6
libreoffice-math-7.6.2.1-48.47.6
libreoffice-officebean-7.6.2.1-48.47.6
libreoffice-pyuno-7.6.2.1-48.47.6
libreoffice-writer-7.6.2.1-48.47.6
libreoffice-writer-extensions-7.6.2.1-48.47.6

Описание

A flaw was found in the Libreoffice package. An attacker can craft an odb containing a "database/script" file with a SCRIPT command where the contents of the file could be written to a new file whose location was determined by the attacker.


Затронутые продукты
SUSE Linux Enterprise Software Development Kit 12 SP5:frozen-devel-1.1.1-8.3.3
SUSE Linux Enterprise Software Development Kit 12 SP5:libetonyek-0_1-1-0.1.10-10.11.2
SUSE Linux Enterprise Software Development Kit 12 SP5:libetonyek-devel-0.1.10-10.11.2
SUSE Linux Enterprise Software Development Kit 12 SP5:libetonyek-devel-doc-0.1.10-10.11.2

Ссылки
Уязвимость SUSE-SU-2023:4648-1