GLSA Advocate
Joined: 12 May 2004 Posts: 2663
|
Posted: Fri Nov 04, 2016 8:26 am Post subject: [ GLSA 201611-03 ] LibreOffice, OpenOffice |
|
|
Gentoo Linux Security Advisory
Title: LibreOffice, OpenOffice: Multiple vulnerabilities (GLSA 201611-03)
Severity: normal
Exploitable: remote
Date: November 04, 2016
Bug(s): #565026, #587566
ID: 201611-03
Synopsis
Multiple vulnerabilities have been found in both LibreOffice and
OpenOffice, the worst of which allows for the remote execution of arbitrary
code.
Background
LibreOffice is a powerful office suite; its clean interface and powerful
tools let you unleash your creativity and grow your productivity.
Apache OpenOffice is the leading open-source office software suite for
word processing, spreadsheets, presentations, graphics, databases and
more.
Affected Packages
Package: app-office/libreoffice
Vulnerable: < 5.1.4.2
Unaffected: >= 5.1.4.2
Architectures: All supported architectures
Package: app-office/libreoffice-bin
Vulnerable: < 5.1.4.2
Unaffected: >= 5.1.4.2
Architectures: All supported architectures
Package: app-office/openoffice-bin
Vulnerable: < 4.1.2
Unaffected: >= 4.1.2
Architectures: All supported architectures
Description
Multiple vulnerabilities have been found in both LibreOffice and
OpenOffice. Please review the referenced CVE’s for specific
information regarding each.
Impact
Remote attackers could obtain sensitive information, cause a Denial of
Service condition, or execute arbitrary code.
Workaround
There is no known work around at this time.
Resolution
All LibreOffice users should upgrade their respective packages to the
latest version:
Code: | # emerge --sync
# emerge --ask --oneshot --verbose ">=app-office/libreoffice-5.1.4.2"
# emerge --ask --oneshot --verbose
">=app-office/libreoffice-bin-debug-5.1.4.2" | All OpenOffice users should upgrade to the latest version: Code: | # emerge --sync
# emerge --ask --oneshot --verbose ">=app-office/openoffice-bin-4.1.2" |
References
CVE-2015-4551
CVE-2015-5212
CVE-2015-5213
CVE-2015-5214
CVE-2016-4324 |
|