UbuntuUpdates.org

Package "liblibreofficekitgtk"

Name: liblibreofficekitgtk

Description:

GTK3 widget wrapping LibreOffice functionality

Latest version: 1:7.3.7-0ubuntu0.22.04.10
Release: jammy (22.04)
Level: updates
Repository: main
Head package: libreoffice
Homepage: http://www.libreoffice.org

Links


Download "liblibreofficekitgtk"


Other versions of "liblibreofficekitgtk" in Jammy

Repository Area Version
base main 1:7.3.2-0ubuntu2
security main 1:7.3.7-0ubuntu0.22.04.10
backports main 4:25.2.6-0ubuntu0.25.04.1~bpo22.04.1
PPA: LibreOffice 4:25.2.6~rc2-0ubuntu0.22.04.1~lo1

Changelog

Version: 1:7.3.7-0ubuntu0.22.04.10 2025-05-08 19:07:38 UTC

  libreoffice (1:7.3.7-0ubuntu0.22.04.10) jammy-security; urgency=medium

  * SECURITY UPDATE: PDF signature forgery with adbe.pkcs7.sha1 SubFilter
    - debian/patches/CVE-2025-2866.patch: Improve adbe.pkcs7.sha1 signature
      verification
    - CVE-2025-2866

 -- Rico Tzschichholz <email address hidden> Mon, 05 May 2025 17:20:55 +0200

Source diff to previous version
CVE-2025-2866 Improper Verification of Cryptographic Signature vulnerability in LibreOffice allows PDF Signature Spoofing by Improper Validation. In the affect

Version: 1:7.3.7-0ubuntu0.22.04.9 2025-03-10 21:07:10 UTC

  libreoffice (1:7.3.7-0ubuntu0.22.04.9) jammy-security; urgency=medium

  * SECURITY UPDATE: Macro URL arbitrary script execution
    - debian/patches/CVE-2025-1080.patch: Filter out more unwanted command
      URIs
    - CVE-2025-1080

 -- Rico Tzschichholz <email address hidden> Thu, 06 Mar 2025 08:58:09 +0100

Source diff to previous version
CVE-2025-1080 LibreOffice supports Office URI Schemes to enable browser integration of LibreOffice with MS SharePoint server. An additional scheme 'vnd.libreoffice

Version: 1:7.3.7-0ubuntu0.22.04.8 2025-01-27 21:07:20 UTC

  libreoffice (1:7.3.7-0ubuntu0.22.04.8) jammy-security; urgency=medium

  * SECURITY UPDATE: Path traversal leading to arbitrary .ttf file write
    - debian/patches/CVE-2024-12425.patch: be conservative on allowed temp
      font names
    - CVE-2024-12425
  * SECURITY UPDATE: URL fetching can be used to exfiltrate arbitrary INI
      file values and environment variables
    - debian/patches/CVE-2024-12426-1.patch: consider VndSunStarExpand an
      exotic protocol
    - debian/patches/CVE-2024-12426-2.patch: look at 'embedded' protocols too
    - CVE-2024-12426
    - debian/patches/CVE-2024-12426-3.patch: Fix check for further exotic
      protocols

 -- Rico Tzschichholz <email address hidden> Thu, 23 Jan 2025 14:54:13 +0100

Source diff to previous version
CVE-2024-12425 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in The Document Foundation LibreOffice allows Absolute P
CVE-2024-12426 Exposure of Environmental Variables and arbitrary INI file values to an Unauthorized Actor vulnerability in The Document Foundation LibreOffice.

Version: 1:7.3.7-0ubuntu0.22.04.7 2024-09-19 17:07:03 UTC

  libreoffice (1:7.3.7-0ubuntu0.22.04.7) jammy-security; urgency=medium

  * SECURITY UPDATE: Signatures in "repair mode" should not be trusted
    - debian/patches/CVE-2024-7788.patch: sfx2: SfxObjectShell should
      not trust any signature on repaired package
    - CVE-2024-7788

 -- Rico Tzschichholz <email address hidden> Wed, 18 Sep 2024 17:10:51 +0200

Source diff to previous version
CVE-2024-7788 Improper Digital Signature InvalidationĀ  vulnerability in Zip Repair Mode of The Document Foundation LibreOffice allows Signature forgery vulnerabili

Version: 1:7.3.7-0ubuntu0.22.04.6 2024-08-15 18:07:19 UTC

  libreoffice (1:7.3.7-0ubuntu0.22.04.6) jammy-security; urgency=medium

  * SECURITY UPDATE: Ability to trust not validated macro signatures
    removed in high security mode (LP: #2076130)
    - debian/patches/CVE-2024-6472.patch: remove ability to trust not
      validated macro signatures in high security
    - CVE-2024-6472

 -- Rico Tzschichholz <email address hidden> Mon, 05 Aug 2024 21:22:27 +0200

2076130 CVE-2024-6472
CVE-2024-6472 Certificate Validation user interface in LibreOffice allows potential vulnerability. Signed macros are scripts that have been digitally signed by



About   -   Send Feedback to @ubuntu_updates