Lucene search

K
oraclelinuxOracleLinuxELSA-2024-1514
HistoryMar 28, 2024 - 12:00 a.m.

libreoffice security fix update

2024-03-2800:00:00
linux.oracle.com
7
libreoffice
security update
fix
cve-2023-6185
cve-2023-6186
gstreamer
link target protocols
unix
oracle
configure
vendor.

8.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

6.6 Medium

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

28.7%

[6.4.7.2-16.0.1]

  • Replace colors with Oracle colors [Orabug: 32120093]
  • Build with --with-vendor=‘Oracle America, Inc.’
  • Added the --with-hamcrest option to configure.
    [1:6.4.7.2-16]
  • Fix CVE-2023-6185 escape url passed to gstreamer
  • Fix CVE-2023-6186 check link target protocols

8.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

6.6 Medium

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

28.7%