Lucene search

K
redhatRedHatRHSA-2020:1598
HistoryApr 28, 2020 - 8:55 a.m.

(RHSA-2020:1598) Moderate: libreoffice security and bug fix update

2020-04-2808:55:11
access.redhat.com
64

0.971 High

EPSS

Percentile

99.8%

LibreOffice is an open source, community-developed office productivity suite. It includes key desktop applications, such as a word processor, a spreadsheet, a presentation manager, a formula editor, and a drawing program. LibreOffice replaces OpenOffice and provides a similar but enhanced and extended office suite.

Security Fix(es):

  • libreoffice: Insufficient URL validation allowing LibreLogo script execution (CVE-2019-9850)

  • libreoffice: LibreLogo global-event script execution (CVE-2019-9851)

  • libreoffice: Insufficient URL encoding flaw in allowed script location check (CVE-2019-9852)

  • libreoffice: Insufficient URL decoding flaw in categorizing macro location (CVE-2019-9853)

  • libreoffice: Unsafe URL assembly flaw in allowed script location check (CVE-2019-9854)

  • libreoffice: Remote resources protection module not applied to bullet graphics (CVE-2019-9849)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Additional Changes:

For detailed information on changes in this release, see the Red Hat Enterprise Linux 8.2 Release Notes linked from the References section.