FlawAtlas
Search the atlas
SUSE-SU-2015:1915-1 Not scored

Recommended update for LibreOffice

This update brings LibreOffice to version 5.0.2, a major version update. It brings lots of new features, bugfixes and also security fixes. Features as seen on http://www.libreoffice.org/discover/new-features/ * LibreOffice 5.0 ships an impressive number of new features for its spreadsheet module, Calc: complex formulae image cropping, new functions, more powerful conditional formatting, table addressing and much more. Calc's blend of performance and features makes it an enterprise-ready, heavy duty spreadsheet application capable of handling all kinds of workload for an impressive range of use cases * New icons, major improvements to menus and sidebar : no other LibreOffice version has looked that good and helped you be creative and get things done the right way. In addition, style management is now more intuitive thanks to the visualization of styles right in the interface. * LibreOffice 5 ships with numerous improvements to document import and export filters for MS Office, PDF, RTF, and more. You can now timestamp PDF documents generated with LibreOffice and enjoy enhanced document conversion fidelity all around. The Pentaho Flow Reporting Engine is now added and used. Security issues fixed: * CVE-2014-8146: The resolveImplicitLevels function in common/ubidi.c in the Unicode Bidirectional Algorithm implementation in ICU4C in International Components for Unicode (ICU) before 55.1 did not properly track directionally isolated pieces of text, which allowed remote attackers to cause a denial of service (heap-based buffer overflow) or possibly execute arbitrary code via crafted text. * CVE-2014-8147: The resolveImplicitLevels function in common/ubidi.c in the Unicode Bidirectional Algorithm implementation in ICU4C in International Components for Unicode (ICU) before 55.1 used an integer data type that is inconsistent with a header file, which allowed remote attackers to cause a denial of service (incorrect malloc followed by invalid free) or possibly execute arbitrary code via crafted text. * CVE-2015-4551: An arbitrary file disclosure vulnerability in Libreoffice and Openoffice Calc and Writer was fixed. * CVE-2015-1774: The HWP filter in LibreOffice allowed remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted HWP document, which triggered an out-of-bounds write. * CVE-2015-5212: A LibreOffice 'PrinterSetup Length' integer underflow vulnerability could be used by attackers supplying documents to execute code as the user opening the document. * CVE-2015-5213: A LibreOffice 'Piece Table Counter' invalid check design error vulnerability allowed attackers supplying documents to execute code as the user opening the document. * CVE-2015-5214: Multiple Vendor LibreOffice Bookmark Status Memory Corruption Vulnerability allowed attackers supplying documents to execute code as the user opening the document.

Exploit probability Not scored
Published October 10, 2015
Required by Not available
Last source change February 4, 2026

02 / AFFECTED SOFTWARE

Affected packages

SUSE:Linux Enterprise Workstation Extension 12 sac
SUSE:Linux Enterprise Workstation Extension 12 cmis-client
SUSE:Linux Enterprise Workstation Extension 12 libabw
SUSE:Linux Enterprise Workstation Extension 12 flute
SUSE:Linux Enterprise Software Development Kit 12 hyphen
SUSE:Linux Enterprise Workstation Extension 12 pentaho-reporting-flow-engine
SUSE:Linux Enterprise Desktop 12 hyphen
SUSE:Linux Enterprise Workstation Extension 12 libreoffice-share-linker
SUSE:Linux Enterprise Desktop 12 librevenge
SUSE:Linux Enterprise Desktop 12 libbase
SUSE:Linux Enterprise Desktop 12 graphite2
SUSE:Linux Enterprise Workstation Extension 12 libpagemaker
SUSE:Linux Enterprise Desktop 12 flute
SUSE:Linux Enterprise Server 12 graphite2
SUSE:Linux Enterprise Desktop 12 libreoffice
SUSE:Linux Enterprise Desktop 12 libloader
SUSE:Linux Enterprise Software Development Kit 12 libfreehand
SUSE:Linux Enterprise Workstation Extension 12 pentaho-libxml
SUSE:Linux Enterprise Server for SAP Applications 12 apache-commons-logging
SUSE:Linux Enterprise Workstation Extension 12 libloader
SUSE:Linux Enterprise Workstation Extension 12 librepository
SUSE:Linux Enterprise Software Development Kit 12 libmwaw
SUSE:Linux Enterprise Desktop 12 cmis-client
SUSE:Linux Enterprise Desktop 12 sac
SUSE:Linux Enterprise Desktop 12 libserializer
SUSE:Linux Enterprise Workstation Extension 12 libbase
SUSE:Linux Enterprise Workstation Extension 12 libcdr
SUSE:Linux Enterprise Workstation Extension 12 libformula
SUSE:Linux Enterprise Software Development Kit 12 libodfgen
SUSE:Linux Enterprise Workstation Extension 12 libetonyek
SUSE:Linux Enterprise Desktop 12 libvoikko
SUSE:Linux Enterprise Desktop 12 libpagemaker
SUSE:Linux Enterprise Workstation Extension 12 libreoffice-voikko
SUSE:Linux Enterprise Workstation Extension 12 libmwaw
SUSE:Linux Enterprise Desktop 12 libreoffice-voikko
SUSE:Linux Enterprise Workstation Extension 12 libvisio
SUSE:Linux Enterprise Desktop 12 libwps
SUSE:Linux Enterprise Workstation Extension 12 libfreehand
SUSE:Linux Enterprise Software Development Kit 12 malaga-suomi
SUSE:Linux Enterprise Desktop 12 liborcus
SUSE:Linux Enterprise Workstation Extension 12 myspell-dictionaries
SUSE:Linux Enterprise Desktop 12 libcdr
SUSE:Linux Enterprise Desktop 12 libmwaw
SUSE:Linux Enterprise Desktop 12 libmspub
SUSE:Linux Enterprise Workstation Extension 12 libreoffice
SUSE:Linux Enterprise Desktop 12 apache-commons-logging
SUSE:Linux Enterprise Workstation Extension 12 malaga-suomi
SUSE:Linux Enterprise Desktop 12 libformula
SUSE:Linux Enterprise Software Development Kit 12 liborcus
SUSE:Linux Enterprise Software Development Kit 12 libabw
SUSE:Linux Enterprise Workstation Extension 12 hyphen
SUSE:Linux Enterprise Desktop 12 liblayout
SUSE:Linux Enterprise Software Development Kit 12 librevenge
SUSE:Linux Enterprise Server for SAP Applications 12 graphite2
SUSE:Linux Enterprise Desktop 12 libetonyek
SUSE:Linux Enterprise Software Development Kit 12 libetonyek
SUSE:Linux Enterprise Workstation Extension 12 libe-book
SUSE:Linux Enterprise Desktop 12 malaga-suomi
SUSE:Linux Enterprise Software Development Kit 12 cmis-client
SUSE:Linux Enterprise Desktop 12 libe-book
SUSE:Linux Enterprise Software Development Kit 12 libcdr
SUSE:Linux Enterprise Workstation Extension 12 libixion
SUSE:Linux Enterprise Desktop 12 libvisio
SUSE:Linux Enterprise Workstation Extension 12 liblangtag
SUSE:Linux Enterprise Server 12 apache-commons-logging
SUSE:Linux Enterprise Desktop 12 libabw
SUSE:Linux Enterprise Desktop 12 liblangtag
SUSE:Linux Enterprise Workstation Extension 12 libgltf
SUSE:Linux Enterprise Desktop 12 libodfgen
SUSE:Linux Enterprise Desktop 12 pentaho-reporting-flow-engine
SUSE:Linux Enterprise Software Development Kit 12 libvisio
SUSE:Linux Enterprise Workstation Extension 12 libfonts
SUSE:Linux Enterprise Desktop 12 libixion
SUSE:Linux Enterprise Desktop 12 pentaho-libxml
SUSE:Linux Enterprise Software Development Kit 12 libixion
SUSE:Linux Enterprise Software Development Kit 12 liblangtag
SUSE:Linux Enterprise Desktop 12 libfonts
SUSE:Linux Enterprise Workstation Extension 12 liborcus
SUSE:Linux Enterprise Workstation Extension 12 libwps
SUSE:Linux Enterprise Workstation Extension 12 apache-commons-logging
SUSE:Linux Enterprise Workstation Extension 12 librevenge
SUSE:Linux Enterprise Software Development Kit 12 graphite2
SUSE:Linux Enterprise Desktop 12 libreoffice-share-linker
SUSE:Linux Enterprise Desktop 12 myspell-dictionaries
SUSE:Linux Enterprise Software Development Kit 12 libvoikko
SUSE:Linux Enterprise Workstation Extension 12 liblayout
SUSE:Linux Enterprise Workstation Extension 12 libserializer
SUSE:Linux Enterprise Desktop 12 libgltf
SUSE:Linux Enterprise Software Development Kit 12 libwps
SUSE:Linux Enterprise Workstation Extension 12 libmspub
SUSE:Linux Enterprise Software Development Kit 12 libmspub
SUSE:Linux Enterprise Workstation Extension 12 libodfgen
SUSE:Linux Enterprise Workstation Extension 12 libvoikko
SUSE:Linux Enterprise Desktop 12 libfreehand
SUSE:Linux Enterprise Desktop 12 librepository
SUSE:Linux Enterprise Software Development Kit 12 libe-book

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities SUSE-SU-2015:1915-1

This update brings LibreOffice to version 5.0.2, a major version update. It brings lots of new features, bugfixes and also security fixes. Features as seen on http://www.libreoffice.org/discover/new-features/ * LibreOffice 5.0 ships an impressive number of new features for its spreadsheet module, Calc: complex formulae image cropping, new functions, more powerful conditional formatting, table addressing and much more. Calc's blend of performance and features makes it an enterprise-ready, heavy duty spreadsheet application capable of handling all kinds of workload for an impressive range of use cases * New icons, major improvements to menus and sidebar : no other LibreOffice version has looked that good and helped you be creative and get things done the right way. In addition, style management is now more intuitive thanks to the visualization of styles right in the interface. * LibreOffice 5 ships with numerous improvements to document import and export filters for MS Office, PDF, RTF, and more. You can now timestamp PDF documents generated with LibreOffice and enjoy enhanced document conversion fidelity all around. The Pentaho Flow Reporting Engine is now added and used. Security issues fixed: * CVE-2014-8146: The resolveImplicitLevels function in common/ubidi.c in the Unicode Bidirectional Algorithm implementation in ICU4C in International Components for Unicode (ICU) before 55.1 did not properly track directionally isolated pieces of text, which allowed remote attackers to cause a denial of service (heap-based buffer overflow) or possibly execute arbitrary code via crafted text. * CVE-2014-8147: The resolveImplicitLevels function in common/ubidi.c in the Unicode Bidirectional Algorithm implementation in ICU4C in International Components for Unicode (ICU) before 55.1 used an integer data type that is inconsistent with a header file, which allowed remote attackers to cause a denial of service (incorrect malloc followed by invalid free) or possibly execute arbitrary code via crafted text. * CVE-2015-4551: An arbitrary file disclosure vulnerability in Libreoffice and Openoffice Calc and Writer was fixed. * CVE-2015-1774: The HWP filter in LibreOffice allowed remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted HWP document, which triggered an out-of-bounds write. * CVE-2015-5212: A LibreOffice 'PrinterSetup Length' integer underflow vulnerability could be used by attackers supplying documents to execute code as the user opening the document. * CVE-2015-5213: A LibreOffice 'Piece Table Counter' invalid check design error vulnerability allowed attackers supplying documents to execute code as the user opening the document. * CVE-2015-5214: Multiple Vendor LibreOffice Bookmark Status Memory Corruption Vulnerability allowed attackers supplying documents to execute code as the user opening the document.

View original source

05 / REFERENCES

Further evidence