USN-2398-1: LibreOffice vulnerability

Ubuntu Security Notice USN-2398-1


5th November, 2014


libreoffice vulnerability


A security issue affects these releases of Ubuntu and its derivatives:



  • Ubuntu 14.10

  • Ubuntu 14.04 LTS


Summary


LibreOffice could be made to crash or run programs if it received specially crafted network traffic.


Software description



  • libreoffice - Office productivity suite


Details


It was discovered that LibreOffice incorrectly handled the Impress remote

control port. An attacker could possibly use this issue to cause Impress to

crash, resulting in a denial of service, or possibly execute arbitrary

code.


Update instructions


The problem can be corrected by updating your system to the following package version:



Ubuntu 14.10:

libreoffice-core 1:4.3.3-0ubuntu1

Ubuntu 14.04 LTS:

libreoffice-core 1:4.2.7-0ubuntu1


To update your system, please follow these instructions: http://bit.ly/1aJDvTw.


This update uses a new upstream release, which includes additional bug

fixes. After a standard system update you need to restart LibreOffice to

make all the necessary changes.


References


CVE-2014-3693






from Ubuntu Security Notices http://bit.ly/1uvSgrC