Debian alert DLA-4205-1 (libreoffice)
| From: | Daniel Leidert <dleidert@debian.org> | |
| To: | debian-lts-announce@lists.debian.org | |
| Subject: | [SECURITY] [DLA 4205-1] libreoffice security update | |
| Date: | Sun, 01 Jun 2025 15:43:44 +0200 | |
| Message-ID: | <7450ed9d9744fe933c56ba62d0cf305003cae18f.camel@debian.org> |
------------------------------------------------------------------------- Debian LTS Advisory DLA-4205-1 debian-lts@lists.debian.org https://www.debian.org/lts/security/ Daniel Leidert June 01, 2025 https://wiki.debian.org/LTS ------------------------------------------------------------------------- Package : libreoffice Version : 1:7.0.4-4+deb11u13 CVE ID : CVE-2025-1080 CVE-2025-2866 Multiple vulnerabilities were discovered in Libreoffice, an office productivity software suite. CVE-2025-1080 LibreOffice supports Office URI Schemes to enable browser integration of LibreOffice with MS SharePoint server. An additional scheme 'vnd.libreoffice.command' specific to LibreOffice was added. In the affected versions of LibreOffice a link in a browser using that scheme could be constructed with an embedded inner URL that when passed to LibreOffice could call internal macros with arbitrary arguments. CVE-2025-2866 LibreOffice allows PDF Signature Spoofing by Improper Validation. In the affected versions of LibreOffice a flaw in the verification code for adbe.pkcs7.sha1 signatures could cause invalid signatures to be accepted as valid For Debian 11 bullseye, these problems have been fixed in version 1:7.0.4-4+deb11u13. We recommend that you upgrade your libreoffice packages. For the detailed security status of libreoffice please refer to its security tracker page at: https://security-tracker.debian.org/tracker/libreoffice Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS
Attachment: signature.asc (type=application/pgp-signature)
-----BEGIN PGP SIGNATURE----- iQIzBAABCgAdFiEEvu1N7VVEpMA+KD3HS80FZ8KW0F0FAmg8WRAACgkQS80FZ8KW 0F03BxAA05/UFofnJwkgUxNLjZpYRQIKyAvXzayd8hSfXIyoCG0Zzc9bIcC9ApVk LniU3mhYozcmV5Dbe6OCkb3WVkOywWLjVDqKfPNUHMYzQ38U6JfX7ONP9WRPFCJM Zk7FBDkv5p7VAE6Rm7u7dgpUBtk9Lyq9WBFIOYzYryExA8D21417t7XJ8ULnCKJk XvjlIVQ4JDv9ZhOX/RYRImghvW0IdjFMCN6MWD6y8maw/xuaux/ESNVRBBh6uBdK zpbXOcx4Ofn3x2oQ5zHZkQCiRQnSSFnUpv8Srbv277eRdhBkIeIHD/57uSyRXlxS Lp4mhG3tBTBulARxWIQw8DXlYNrdgBKGS0B7sSaU+YHHcSg+wzhw1fqSuOL1NT3W Kv5e3yhIlEj5CySgszrffyb5gN/O6WiTgSREHF0fZE8SW+VAX4yIGWqtcD+wmGgv 4cnEu3VI6QfusjF1p938GNXFZTdiVxV+3Ml8lQIuHpOvjtz225D8pqQKu9bLCgas FnJORjLG5rmJKzWdBBDbemwzs2YV0bsNjqy5pbf/BNntbdrnZb4wHv8g40FYsrv5 aaJcfivVb8PM6ORei1s2OXfYedJfy0ASaa2otL7OWEq9mePKF9yj60PCLQGt7PbA QI2aDkDJwOtamlhLYrDXlZt74CN991coq+g6Xkqa1AE73Vld9/A= =ArzW -----END PGP SIGNATURE-----
