[ubuntu/focal-updates] libreoffice 1:6.4.7-0ubuntu0.20.04.6 (Accepted)
Ubuntu Archive Robot
ubuntu-archive-robot at lists.canonical.com
Thu Oct 20 14:04:30 UTC 2022
libreoffice (1:6.4.7-0ubuntu0.20.04.6) focal-security; urgency=medium
* SECURITY UPDATE: arbitrary script execution via Office URI Schemes
- debian/patches/CVE-2022-3140-1.patch: commands are always URLs in
wizards/source/access2base/DoCmd.xba.
- debian/patches/CVE-2022-3140-2.patch: filter out unwanted command
URIs in desktop/source/app/cmdlineargs.cxx.
- debian/patches/CVE-2022-3140-3.patch: check IFrame FrameURL target in
sfx2/source/appl/macroloader.cxx, sfx2/source/doc/iframe.cxx,
sfx2/source/inc/macroloader.hxx, sw/source/filter/html/htmlplug.cxx,
sw/source/filter/xml/xmltexti.cxx.
- debian/patches/CVE-2022-3140-4.patch: check impress/calc IFrame
FrameURL target in xmloff/source/draw/ximpshap.cxx.
- CVE-2022-3140
Date: 2022-10-18 11:45:08.636378+00:00
Changed-By: Marc Deslauriers <marc.deslauriers at canonical.com>
Signed-By: Ubuntu Archive Robot <ubuntu-archive-robot at lists.canonical.com>
https://launchpad.net/ubuntu/+source/libreoffice/1:6.4.7-0ubuntu0.20.04.6
-------------- next part --------------
Sorry, changesfile not available.
More information about the Focal-changes
mailing list