[ubuntu/bionic-updates] libreoffice 1:6.0.7-0ubuntu0.18.04.12 (Accepted)
Ubuntu Archive Robot
ubuntu-archive-robot at lists.canonical.com
Thu Oct 20 14:04:15 UTC 2022
libreoffice (1:6.0.7-0ubuntu0.18.04.12) bionic-security; urgency=medium
* SECURITY UPDATE: document encryption stripped via recovery
- debian/patches/CVE-2020-12801-1.patch: store ODF encryption data for
autorecovery in comphelper/source/misc/docpasswordhelper.cxx,
sfx2/source/dialog/filedlghelper.cxx.
- debian/patches/CVE-2020-12801-2.patch: keep encryption information
for autorecovered MS formats in
comphelper/source/misc/docpasswordhelper.cxx,
package/source/xstor/owriteablestream.cxx,
package/source/xstor/owriteablestream.hxx,
package/source/xstor/xstorage.cxx, sfx2/source/appl/appopen.cxx.
- debian/patches/CVE-2020-12801-3.patch: use TypeDetection on load in
framework/source/services/autorecovery.cxx.
- CVE-2020-12801
* SECURITY UPDATE: file overwrite via forms
- debian/patches/CVE-2020-12803.patch: limit forms to http[s] in
forms/source/xforms/submission.cxx,
forms/source/xforms/submission/submission.hxx.
- CVE-2020-12803
* SECURITY UPDATE: Improper Certificate Validation vulnerability
- debian/patches/CVE-2022-26305.patch: compare authors using Thumbprint
in xmlsecurity/source/component/documentdigitalsignatures.cxx.
- CVE-2022-26305
* SECURITY UPDATE: stored passwords IV always the same
- debian/patches/CVE-2022-26306-pre1.patch: properly handle failure
decoding master password in
svl/source/passwordcontainer/passwordcontainer.cxx,
svl/source/passwordcontainer/passwordcontainer.hxx.
- debian/patches/CVE-2022-26306-1.patch: simplify Sequence iterations
in svl in svl/source/passwordcontainer/passwordcontainer.cxx.
- debian/patches/CVE-2022-26306-2.patch: add Initialization Vectors to
password storage in
officecfg/registry/schema/org/openoffice/Office/Common.xcs,
svl/source/passwordcontainer/passwordcontainer.cxx,
svl/source/passwordcontainer/passwordcontainer.hxx.
- CVE-2022-26306
* SECURITY UPDATE: password storage master key weak entropy
- debian/patches/CVE-2022-26307-1.patch: make hash encoding match
decoding in
officecfg/registry/schema/org/openoffice/Office/Common.xcs,
svl/source/passwordcontainer/passwordcontainer.cxx,
svl/source/passwordcontainer/passwordcontainer.hxx,
uui/source/iahndl-authentication.cxx.
- debian/patches/CVE-2022-26307-2.patch: add infobar to prompt to
refresh to replace old format in include/sfx2/strings.hrc,
include/sfx2/viewfrm.hxx, sfx2/source/view/viewfrm.cxx.
- CVE-2022-26307
* SECURITY UPDATE: arbitrary script execution via Office URI Schemes
- debian/patches/CVE-2022-3140-pre1.patch: warn on load when a document
binds an event to a macro in comphelper/source/misc/documentinfo.cxx,
dbaccess/source/core/dataaccess/ModelImpl.cxx,
dbaccess/source/core/dataaccess/databasedocument.cxx,
dbaccess/source/core/inc/ModelImpl.hxx,
include/comphelper/documentinfo.hxx, include/oox/ole/axcontrol.hxx,
include/sfx2/docmacromode.hxx, include/sfx2/objsh.hxx,
include/xmloff/xmlimp.hxx, oox/source/ole/vbaproject.cxx,
sc/source/filter/excel/xiescher.cxx,
sc/source/filter/inc/xiescher.hxx,
sc/source/ui/vba/vbasheetobject.cxx,
sc/source/ui/vba/vbasheetobject.hxx,
scripting/source/protocolhandler/scripthandler.cxx,
sfx2/source/doc/docmacromode.cxx, sfx2/source/doc/objmisc.cxx,
sfx2/source/doc/objstor.cxx, sfx2/source/doc/objxtor.cxx,
sfx2/source/doc/sfxbasemodel.cxx, sfx2/source/inc/objshimp.hxx,
sw/source/filter/html/htmlform.cxx,
sw/source/filter/html/htmlgrin.cxx, sw/source/filter/html/swhtml.cxx,
sw/source/filter/ww8/ww8par.cxx, sw/source/filter/ww8/ww8par.hxx,
sw/source/filter/ww8/ww8par5.cxx, xmloff/source/core/xmlimp.cxx,
xmloff/source/script/XMLEventImportHelper.cxx.
- debian/patches/CVE-2022-3140-1.patch: commands are always URLs in
wizards/source/access2base/DoCmd.xba.
- debian/patches/CVE-2022-3140-2.patch: filter out unwanted command
URIs in desktop/source/app/cmdlineargs.cxx.
- debian/patches/CVE-2022-3140-3.patch: check IFrame FrameURL target in
sfx2/source/appl/macroloader.cxx, sfx2/source/doc/iframe.cxx,
sfx2/source/inc/macroloader.hxx, sw/source/filter/html/htmlplug.cxx,
sw/source/filter/xml/xmltexti.cxx.
- debian/patches/CVE-2022-3140-4.patch: check impress/calc IFrame
FrameURL target in xmloff/source/draw/ximpshap.cxx.
- CVE-2022-3140
Date: 2022-10-18 11:33:11.193148+00:00
Changed-By: Marc Deslauriers <marc.deslauriers at canonical.com>
Signed-By: Ubuntu Archive Robot <ubuntu-archive-robot at lists.canonical.com>
https://launchpad.net/ubuntu/+source/libreoffice/1:6.0.7-0ubuntu0.18.04.12
-------------- next part --------------
Sorry, changesfile not available.
More information about the Bionic-changes
mailing list