USN-6789-1: LibreOffice vulnerability

Publication date

28 May 2024

Overview

LibreOffice could be made to run programs when clicking a graphic.


Packages

Details

Amel Bouziane-Leblond discovered that LibreOffice incorrectly handled
graphic on-click bindings. If a user were tricked into clicking a graphic
in a specially crafted document, a remote attacker could possibly run
arbitrary script.

Amel Bouziane-Leblond discovered that LibreOffice incorrectly handled
graphic on-click bindings. If a user were tricked into clicking a graphic
in a specially crafted document, a remote attacker could possibly run
arbitrary script.

Update instructions

In general, a standard system update will make all the necessary changes.

Learn more about how to get the fixes.

The problem can be corrected by updating your system to the following package versions:

Ubuntu Release Package Version
24.04 noble libreoffice –  4:24.2.3-0ubuntu0.24.04.2
23.10 mantic libreoffice –  4:7.6.7-0ubuntu0.23.10.2
22.04 jammy libreoffice –  1:7.3.7-0ubuntu0.22.04.5
20.04 focal libreoffice –  1:6.4.7-0ubuntu0.20.04.10

Reduce your security exposure

Ubuntu Pro provides ten-year security coverage to 25,000+ packages in Main and Universe repositories, and it is free for up to five machines.


Have additional questions?

Talk to a member of the team ›