DSA-4022-1 libreoffice -- security update

Related Vulnerabilities: CVE-2017-12607   CVE-2017-12608  

Marcin Noga discovered two vulnerabilities in LibreOffice, which could result in the execution of arbitrary code if a malformed PPT or DOC document is opened. For the oldstable distribution (jessie), these problems have been fixed in version 1:4.3.3-2+deb8u9. These vulnerabilities were fixed in Libreoffice 5.0.2, so the version in the stable distribution (stretch) is not affected. We recommend that you upgrade your libreoffice packages.

Debian Security Advisory

DSA-4022-1 libreoffice -- security update

Date Reported:
07 Nov 2017
Affected Packages:
libreoffice
Vulnerable:
Yes
Security database references:
In Mitre's CVE dictionary: CVE-2017-12607, CVE-2017-12608.
More information:

Marcin Noga discovered two vulnerabilities in LibreOffice, which could result in the execution of arbitrary code if a malformed PPT or DOC document is opened.

For the oldstable distribution (jessie), these problems have been fixed in version 1:4.3.3-2+deb8u9.

These vulnerabilities were fixed in Libreoffice 5.0.2, so the version in the stable distribution (stretch) is not affected.

We recommend that you upgrade your libreoffice packages.