Jump to content

Build Theme!
  •  
  • Infected?

WE'RE SURE THAT YOU'LL LOVE US!

Hey there! :wub: Looks like you're enjoying the discussion, but you're not signed up for an account. When you create an account, we remember exactly what you've read, so you always come right back where you left off. You also get notifications, here and via email, whenever new posts are made. You can like posts to share the love. :D Join 93116 other members! Anybody can ask, anybody can answer. Consistently helpful members may be invited to become staff. Here's how it works. Virus cleanup? Start here -> Malware Removal Forum.

Try What the Tech -- It's free!


Photo

LibreOffice updates


  • Please log in to reply
1 reply to this topic

#1 AplusWebMaster

AplusWebMaster

    AplusWebMaster

  • Authentic Member
  • PipPipPipPipPipPipPip
  • 10,472 posts
  • Interests:... The never-ending battle for Truth, Justice, and the American way.

Posted 06 November 2015 - 07:16 AM

FYI...

LibreOffice 4.4.6/5.0.0 released
- https://www.libreoff.../cve-2015-4551/
Nov 5, 2015 - "The LinkUpdateMode feature controls whether documents inserted into Writer or Calc via links will either not get updated, or prompt to update, or automatically update, when the parent document is loaded. The configuration of this option was stored in the document. That flawed approach enabled documents to be crafted with links to plausible targets on the victims host computer. The contents of those automatically inserted after load links can be concealed in hidden sections and retrieved by the attacker if the document is saved and returned to sender, or via http requests if the user has selected lower security settings for that document..."
- https://www.libreoff.../cve-2015-5214/
Nov 5, 2015 - "Fixed in: LibreOffice 4.4.6/5.0.0
Description: The indexes into the bookmark array were insufficiently checked for validity. A document can be constructed which refers to bookmarks that don't exist, causing memory corruption.
All users are recommended to upgrade to LibreOffice >= 4.4.6 or >= 5.0.0"

Release Notes
- https://www.libreoff.../release-notes/

 

Security Advisories
> https://www.libreoff...ity/advisories/

Download
- https://www.libreoff...reoffice-still/
___

- http://www.securityt....com/id/1034085
CVE Reference: CVE-2015-4551, CVE-2015-5212, CVE-2015-5213
Nov 5 2015
Version(s): prior to 4.4.5 ...
Impact: A remote user can create content that, when loaded by the target user, will execute arbitrary code or obtain files on the target user's system.
Solution: The vendor has issued a fix (4.4.5, 5.0.0).
The vendor's advisories are available at:
- https://www.libreoff.../cve-2015-4551/
- https://www.libreoff.../cve-2015-5212/
- https://www.libreoff.../cve-2015-5213/

- http://www.securityt....com/id/1034086
CVE Reference: CVE-2015-5214
Nov 5 2015
Fix Available: Yes  Vendor Confirmed:  Yes  
Version(s): prior to 4.4.6 ...
Impact: A remote user can create content that, when loaded by the target user, will execute arbitrary code on the target user's system.
Solution: The vendor has issued a fix (4.4.6, 5.0.0).
The vendor's advisory is available at:
- https://www.libreoff.../cve-2015-5214/
Fixed in: LibreOffice 4.4.6/5.0.0
 

:ph34r: :ph34r:


Edited by AplusWebMaster, 28 November 2015 - 06:57 AM.

.The machine has no brain.
 ......... Use your own.
Browser check for updates here.
YOU need to defend against -all- vulnerabilities.
Hacks only need to find -1- to get in...
.

    Advertisements

Register to Remove


#2 AplusWebMaster

AplusWebMaster

    AplusWebMaster

  • Authentic Member
  • PipPipPipPipPipPipPip
  • 10,472 posts
  • Interests:... The never-ending battle for Truth, Justice, and the American way.

Posted 30 June 2016 - 08:58 AM

FYI...

LibreOffice 5.1.4 released
- http://www.securityt....com/id/1036209
CVE Reference: https://cve.mitre.or...e=CVE-2016-4324
Jun 30 2016
Fix Available:  Yes  Vendor Confirmed:  Yes  
Version(s): prior to 5.1.4 ...
Impact: A remote user can create a file that, when loaded by the target user, will execute arbitrary code on the target user's system.
Solution: The vendor has issued a fix (5.1.4, 5.2.0 prerelease)...

- https://www.libreoff.../cve-2016-4324/
June 28, 2016 - Fixed in: LibreOffice 5.1.4/5.2.0
- https://www.libreoff.../release-notes/

> https://www.libreoff...reoffice-fresh/
___

- https://blogs.cisco....ght-libreoffice
June 28, 2016
 

:ph34r: :ph34r:


Edited by AplusWebMaster, 05 July 2016 - 06:37 AM.

.The machine has no brain.
 ......... Use your own.
Browser check for updates here.
YOU need to defend against -all- vulnerabilities.
Hacks only need to find -1- to get in...
.

Related Topics



1 user(s) are reading this topic

0 members, 1 guests, 0 anonymous users