Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 908083 (CVE-2023-0950, CVE-2023-2255) - <app-office/libreoffice{-bin,}-7.5.3.2: multiple vulnerabilities
Summary: <app-office/libreoffice{-bin,}-7.5.3.2: multiple vulnerabilities
Status: RESOLVED FIXED
Alias: CVE-2023-0950, CVE-2023-2255
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal major (vote)
Assignee: Gentoo Security
URL:
Whiteboard: A2 [glsa+]
Keywords: PullRequest
Depends on: 905701
Blocks:
  Show dependency tree
 
Reported: 2023-06-09 04:03 UTC by John Helmert III
Modified: 2023-11-26 07:58 UTC (History)
0 users

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2023-06-09 04:03:00 UTC
CVE-2023-0950 (https://www.libreoffice.org/about-us/security/advisories/CVE-2023-0950):

Improper Validation of Array Index vulnerability in the spreadsheet component of The Document Foundation LibreOffice allows an attacker to craft a spreadsheet document that will cause an array index underflow when loaded. In the affected versions of LibreOffice certain malformed spreadsheet formulas, such as AGGREGATE, could be created with less parameters passed to the formula interpreter than it expected, leading to an array index underflow, in which case there is a risk that arbitrary code could be executed. This issue affects: The Document Foundation LibreOffice 7.4 versions prior to 7.4.6; 7.5 versions prior to 7.5.1.

CVE-2023-2255 (https://www.libreoffice.org/about-us/security/advisories/CVE-2023-2255):

Improper access control in editor components of The Document Foundation LibreOffice allowed an attacker to craft a document that would cause external links to be loaded without prompt. In the affected versions of LibreOffice documents that used "floating frames" linked to external files, would load the contents of those frames without prompting the user for permission to do so. This was inconsistent with the treatment of other linked content in LibreOffice. This issue affects: The Document Foundation LibreOffice 7.4 versions prior to 7.4.7; 7.5 versions prior to 7.5.3.
Comment 1 Larry the Git Cow gentoo-dev 2023-06-09 14:31:30 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=d49c2ef763d228c0d7958a70f6ff6bd7c5629fd3

commit d49c2ef763d228c0d7958a70f6ff6bd7c5629fd3
Author:     Andreas K. Hüttel <dilfridge@gentoo.org>
AuthorDate: 2023-06-09 14:30:37 +0000
Commit:     Andreas K. Hüttel <dilfridge@gentoo.org>
CommitDate: 2023-06-09 14:31:18 +0000

    app-office/libreoffice-bin-debug: drop 7.4.6.2, 7.4.6.2-r1
    
    Bug: https://bugs.gentoo.org/908083
    Signed-off-by: Andreas K. Hüttel <dilfridge@gentoo.org>

 app-office/libreoffice-bin-debug/Manifest          | 18 -----
 .../libreoffice-bin-debug-7.4.6.2-r1.ebuild        | 85 ----------------------
 .../libreoffice-bin-debug-7.4.6.2.ebuild           | 85 ----------------------
 3 files changed, 188 deletions(-)
Comment 2 Larry the Git Cow gentoo-dev 2023-06-10 09:39:12 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=2df4c43f17ff05e2bf30a9c3f8329cd0faba035b

commit 2df4c43f17ff05e2bf30a9c3f8329cd0faba035b
Author:     Andreas Sturmlechner <asturm@gentoo.org>
AuthorDate: 2023-06-10 08:53:53 +0000
Commit:     Andreas Sturmlechner <asturm@gentoo.org>
CommitDate: 2023-06-10 09:38:35 +0000

    app-office/libreoffice: drop 7.4.6.2-r1
    
    Bug: https://bugs.gentoo.org/908083
    Signed-off-by: Andreas Sturmlechner <asturm@gentoo.org>

 app-office/libreoffice/Manifest                    |   2 -
 .../libreoffice-7.3.7.2-boost-1.81-locale.patch    |  41 --
 .../libreoffice-7.3.7.2-zxing-cpp-1.4.0.patch      |  59 --
 ...libreoffice-7.4.4.2-zxing-cpp-1.4.0-c++17.patch |  36 --
 .../libreoffice/libreoffice-7.4.6.2-r1.ebuild      | 655 ---------------------
 5 files changed, 793 deletions(-)
Comment 3 Andreas Sturmlechner gentoo-dev 2023-06-10 14:52:45 UTC
(cleanup done, office out)
Comment 4 Larry the Git Cow gentoo-dev 2023-11-26 07:56:50 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/data/glsa.git/commit/?id=be0606522c4483d03f416aa755cb0dc93232da8b

commit be0606522c4483d03f416aa755cb0dc93232da8b
Author:     GLSAMaker <glsamaker@gentoo.org>
AuthorDate: 2023-11-26 07:56:03 +0000
Commit:     Hans de Graaff <graaff@gentoo.org>
CommitDate: 2023-11-26 07:56:43 +0000

    [ GLSA 202311-15 ] LibreOffice: Multiple Vulnerabilities
    
    Bug: https://bugs.gentoo.org/908083
    Signed-off-by: GLSAMaker <glsamaker@gentoo.org>
    Signed-off-by: Hans de Graaff <graaff@gentoo.org>

 glsa-202311-15.xml | 54 ++++++++++++++++++++++++++++++++++++++++++++++++++++++
 1 file changed, 54 insertions(+)