MGASA-2014-0447

Source
https://advisories.mageia.org/MGASA-2014-0447.html
Import Source
https://advisories.mageia.org/MGASA-2014-0447.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2014-0447
Related
Published
2014-11-14T01:24:42Z
Modified
2014-11-14T01:10:23Z
Summary
Updated libreoffice packages fix security vulnerabilities
Details

It was discovered during routine code review that LibreOffice unconditionally executed certain VBA macros on loading Microsoft Office documents, contrary to user expectations (CVE-2014-0247).

A vulnerability in LibreOffice allows an attacker to send a document which when opened will trigger the prompt to "Update Links" but if the user cancels that prompt may still generate and insert into the document an OLE2 preview image of a file on the victims filesystem, Data exposure is possible if the updated document is then distributed to other parties (CVE-2014-3575).

LibreOffice has been updated to version 4.1.6.2 and patched to fix the CVE-2014-0247 and CVE-2014-3575 issues as well as to fix other bugs.

References
Credits

Affected packages

Mageia:4 / libreoffice

Package

Name
libreoffice
Purl
pkg:rpm/mageia/libreoffice?distro=mageia-4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.1.6.2-1.mga4

Ecosystem specific

{
    "section": "core"
}