Lucene search

K
suseSuseOPENSUSE-SU-2019:2057-1
HistorySep 03, 2019 - 12:00 a.m.

Security update for libreoffice (important)

2019-09-0300:00:00
lists.opensuse.org
169

0.971 High

EPSS

Percentile

99.8%

An update that solves 5 vulnerabilities and has one errata
is now available.

Description:

This update for libreoffice fixes the following issues:

Security issues fixed:

  • CVE-2019-9849: Disabled fetching remote bullet graphics in ‘stealth
    mode’ (bsc#1141861).
  • CVE-2019-9848: Fixed an arbitrary script execution via LibreLogo
    (bsc#1141862).
  • CVE-2019-9851: Fixed LibreLogo global-event script execution issue
    (bsc#1146105).
  • CVE-2019-9852: Fixed insufficient URL encoding flaw in allowed script
    location check (bsc#1146107).
  • CVE-2019-9850: Fixed insufficient URL validation that allowed LibreLogo
    script execution (bsc#1146098).

Non-security issue fixed:

  • SmartArt: Basic rendering of Trapezoid List (bsc#1133534)

This update was imported from the SUSE:SLE-15:Update update project.

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods
like YaST online_update or “zypper patch”.

Alternatively you can run the command listed for your product:

  • openSUSE Leap 15.0:

    zypper in -t patch openSUSE-2019-2057=1

OSVersionArchitecturePackageVersionFilename
openSUSE Leap15.0noarch< - openSUSE Leap 15.0 (noarch):- openSUSE Leap 15.0 (noarch):.noarch.rpm
openSUSE Leap15.0x86_64< - openSUSE Leap 15.0 (x86_64):- openSUSE Leap 15.0 (x86_64):.x86_64.rpm