Lucene search

K
suseSuseOPENSUSE-SU-2019:2183-1
HistorySep 25, 2019 - 12:00 a.m.

Security update for libreoffice (moderate)

2019-09-2500:00:00
lists.opensuse.org
77

0.971 High

EPSS

Percentile

99.8%

An update that solves 7 vulnerabilities and has one errata
is now available.

Description:

This update for libreoffice fixes the following issues:

Updated to version 6.2.7.1.

Security issues fixed:

  • CVE-2019-9849: Disabled fetching remote bullet graphics in ‘stealth
    mode’ (bsc#1141861).
  • CVE-2019-9848: Fixed an arbitrary script execution via LibreLogo
    (bsc#1141862).
  • CVE-2019-9851: Fixed LibreLogo global-event script execution issue
    (bsc#1146105).
  • CVE-2019-9852: Fixed insufficient URL encoding flaw in allowed script
    location check (bsc#1146107).
  • CVE-2019-9850: Fixed insufficient URL validation that allowed LibreLogo
    script execution (bsc#1146098).
  • CVE-2019-9854: Fixed unsafe URL assembly flaw (bsc#1149944).
  • CVE-2019-9855: Fixed path equivalence handling flaw (bsc#1149943)

Non-security issue fixed:

  • SmartArt: Basic rendering of Trapezoid List (bsc#1133534).

This update was imported from the SUSE:SLE-15-SP1:Update update project.

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods
like YaST online_update or “zypper patch”.

Alternatively you can run the command listed for your product:

  • openSUSE Leap 15.1:

    zypper in -t patch openSUSE-2019-2183=1

OSVersionArchitecturePackageVersionFilename
openSUSE Leap15.1x86_64< - openSUSE Leap 15.1 (x86_64):- openSUSE Leap 15.1 (x86_64):.x86_64.rpm
openSUSE Leap15.1noarch< - openSUSE Leap 15.1 (noarch):- openSUSE Leap 15.1 (noarch):.noarch.rpm