UbuntuUpdates.org

Package "libunoloader-java"

Name: libunoloader-java

Description:

LibreOffice UNO runtime environment -- (Java) UNO loader

Latest version: 1:7.3.7-0ubuntu0.22.04.4
Release: jammy (22.04)
Level: security
Repository: main
Head package: libreoffice
Homepage: http://www.libreoffice.org

Links


Download "libunoloader-java"


Other versions of "libunoloader-java" in Jammy

Repository Area Version
base main 1:7.3.2-0ubuntu2
updates main 1:7.3.7-0ubuntu0.22.04.4
backports main 4:7.6.5-0ubuntu0.23.10.1~bpo22.04.1
PPA: LibreOffice 4:24.2.1~rc2-0ubuntu0.22.04.1~lo1

Changelog

Version: 1:7.3.7-0ubuntu0.22.04.4 2023-12-14 15:06:54 UTC

  libreoffice (1:7.3.7-0ubuntu0.22.04.4) jammy-security; urgency=medium

  * SECURITY UPDATE: Improper input validation enabling arbitrary Gstreamer
     pipeline injection
    - debian/patches/CVE-2023-6185.patch: escape url passed to gstreamer
    - CVE-2023-6185
  * SECURITY UPDATE: Link targets allow arbitrary script execution
    - debian/patches/CVE-2023-6186-*.patch: multiple commits to fix
      security issues.
    - CVE-2023-6186
  * patches/CppunitTest_desktop_lib-adjust-asserts-so-this-works.patch:
    - Usage of expired certificates in CppunitTest_desktop_lib:
      adjust asserts so this works again

 -- Rico Tzschichholz <email address hidden> Mon, 11 Dec 2023 15:19:13 +0100

Source diff to previous version
CVE-2023-6185 Improper input validation enabling arbitrary Gstreamer pipeline injection
CVE-2023-6186 Link targets allow arbitrary script execution

Version: 1:7.3.7-0ubuntu0.22.04.3 2023-06-07 07:14:23 UTC

  libreoffice (1:7.3.7-0ubuntu0.22.04.3) jammy-security; urgency=high

  * SECURITY UPDATE: Remote documents loaded without prompt via IFrame
    - debian/patches/CVE-2023-2255-*.patch: multiple commits to fix
      security issues.
    - CVE-2023-2255
  * SECURITY UPDATE: Array Index UnderFlow in Calc Formula Parsing
    - debian/patches/CVE-2023-0950.patch: Obtain actual 0-parameter count
      for OR(), AND() and 1-parameter functions
    - CVE-2023-0950

 -- Rico Tzschichholz <email address hidden> Thu, 25 May 2023 22:52:23 +0200

Source diff to previous version
CVE-2023-2255 Improper access control in editor components of The Document Foundation LibreOffice allowed an attacker to craft a document that would cause external
CVE-2023-0950 Improper Validation of Array Index vulnerability in the spreadsheet component of The Document Foundation LibreOffice allows an attacker to craft a sp

Version: 1:7.3.6-0ubuntu0.22.04.2 2022-10-20 15:06:31 UTC

  libreoffice (1:7.3.6-0ubuntu0.22.04.2) jammy-security; urgency=medium

  * SECURITY UPDATE: arbitrary script execution via Office URI Schemes
    - debian/patches/CVE-2022-3140-4.patch: check impress/calc IFrame
      FrameURL target in xmloff/source/draw/ximpshap.cxx.
    - CVE-2022-3140

 -- Marc Deslauriers <email address hidden> Tue, 18 Oct 2022 07:19:40 -0400

CVE-2022-3140 LibreOffice supports Office URI Schemes to enable browser integration of LibreOffice with MS SharePoint server. An additional scheme 'vnd.libreoffice



About   -   Send Feedback to @ubuntu_updates