UbuntuUpdates.org

Package "libreoffice-script-provider-python"

Name: libreoffice-script-provider-python

Description:

Python script support provider for LibreOffice scripting framework

Latest version: 1:7.3.7-0ubuntu0.22.04.13
Release: jammy (22.04)
Level: updates
Repository: universe
Head package: libreoffice
Homepage: http://www.libreoffice.org

Links


Download "libreoffice-script-provider-python"


Other versions of "libreoffice-script-provider-python" in Jammy

Repository Area Version
base universe 1:7.3.2-0ubuntu2
security universe 1:7.3.7-0ubuntu0.22.04.13
backports universe 4:26.2.5.2-0ubuntu0.26.04.1~bpo22.04.1
PPA: LibreOffice 4:26.2.6.3-0ubuntu0.22.04.1~lo1

Changelog

Version: 1:7.3.7-0ubuntu0.22.04.13 2026-10-07 15:38:13 UTC

libreoffice (1:7.3.7-0ubuntu0.22.04.13) jammy-security; urgency=medium

  * SECURITY UPDATE: Mitigation for "OOB write via Graphite actions"
    - debian/patches/CVE-2026-50593.patch: check for hb_shape_full failure
    - CVE-2026-50593
  * SECURITY UPDATE: Heap buffer overflow in WMF text record import
    - debian/patches/CVE-2026-63272.patch: ofz: ignore an advance array shorter
      than the string
    - CVE-2026-63272
  * SECURITY UPDATE: Heap buffer overflow in PDF import encryption handling
    - debian/patches/CVE-2026-63273.patch: ofz: pdf, check record againsts max
      allowed size
    - CVE-2026-63273
  * SECURITY UPDATE: Heap buffer overflow in PDF import stream handling
    - debian/patches/CVE-2026-63274.patch: ofz: pdf, clamp stream Length to the
      bytes actually read
    - CVE-2026-63274
  * SECURITY UPDATE: Stack buffer overflow in CFF font hint handling
    - debian/patches/CVE-2026-63275.patch: ofz: wmf, check record against max
      allowed size
    - CVE-2026-63275
  * SECURITY UPDATE: Package URLs can be used to exfiltrate arbitrary INI
    file values and environment variables
    - debian/patches/CVE-2026-63278.patch: match the package content provider
      when checking a vnd.sun.star.pkg url
    - CVE-2026-63278
  * SECURITY UPDATE: Out of bounds read in PICT image import
    - debian/patches/CVE-2026-63279.patch: limit palette index
    - CVE-2026-63279

 -- Rico Tzschichholz Mon, 28 Sep 2026 10:35:32 +0200

Source diff to previous version
CVE-2026-50593 Graphite before 1.3.15 has an integer underflow and resultant out-of-bounds write via Graphite actions, because slotat does not ensure that an offset
CVE-2026-63272 LibreOffice can import WMF graphics, which may be embedded in documents. A heap buffer overflow existed when importing a text record that carries its
CVE-2026-63273 LibreOffice Draw can import PDF documents. A heap buffer overflow existed when importing an encrypted document. The length of the decryption key was
CVE-2026-63274 LibreOffice Draw can import PDF documents. A heap buffer overflow existed when importing a stream object. The length of the stream was taken from the
CVE-2026-63275 LibreOffice can read CFF fonts, which may be embedded in documents. A stack buffer overflow existed when reading the hints of a glyph. The number of
CVE-2026-63278 URLs could be constructed which expanded environment variable or INI file values, so potentially sensitive information could be exfiltrated to a remo
CVE-2026-63279 LibreOffice can import PICT images, which may be embedded in documents. An out of bounds read existed when importing an image that uses a colour pale

Version: 1:7.3.7-0ubuntu0.22.04.12 2026-07-13 22:09:24 UTC

  libreoffice (1:7.3.7-0ubuntu0.22.04.12) jammy-security; urgency=medium

  * SECURITY UPDATE: Heap buffer overflow in DXF polyline import
    - debian/patches/CVE-2026-6039.patch: stay within max Polygon points
    - CVE-2026-6039
  * SECURITY UPDATE: Heap buffer overflow in EMF+ gradient brush import
    - debian/patches/CVE-2026-6045-0.patch: EMF+ Use variable types according to
      EMFPLUS documentation
    - debian/patches/CVE-2026-6045-1.patch: check that the file can provide the
      claimed data
    - debian/patches/CVE-2026-6045-2.patch: tidy up emfppath.cxx edge cases
    - debian/patches/CVE-2026-6045-3.patch: check that the file can provide the
      claimed data
    - CVE-2026-6045
  * SECURITY UPDATE: Stack buffer overflow in PPT presentation import
    - debian/patches/CVE-2026-8356.patch: SdrEscherImport::RecolorGraphic
      reads but doesn't use FillColors
    - CVE-2026-8356
  * SECURITY UPDATE: Heap buffer overflow in Calc formula compilation
    - debian/patches/CVE-2026-8357.patch: A formula of length L, composed
      entirely of open tokens, needs L+1 slots
    - CVE-2026-8357
  * SECURITY UPDATE: Heap buffer overflow in spreadsheet tracked-changes import
    - debian/patches/CVE-2026-8358.patch: drop malformed duplicate-id calc
      change track actions
    - CVE-2026-8358

 -- Rico Tzschichholz <email address hidden> Sun, 28 Jun 2026 12:36:00 +0200

Source diff to previous version
CVE-2026-6039 LibreOffice can import drawings in the DXF format used by CAD software. A heap buffer overflow existed when importing a DXF polyline. The point count
CVE-2026-6045 LibreOffice can import EMF+ graphics, which may be embedded in documents. A heap buffer overflow existed when importing an EMF+ gradient brush. The n
CVE-2026-8356 LibreOffice can import presentations in the legacy binary PPT format. A stack buffer overflow existed when importing a colour-replacement record. Two
CVE-2026-8357 LibreOffice Calc compiles cell formulas when opening a spreadsheet. A heap buffer overflow existed when compiling a very long formula made up of many
CVE-2026-8358 LibreOffice Calc can import tracked changes from a spreadsheet document. A heap buffer overflow existed when a document reused the same change identi

Version: 1:7.3.7-0ubuntu0.22.04.11 2026-05-29 02:07:35 UTC

  libreoffice (1:7.3.7-0ubuntu0.22.04.11) jammy-security; urgency=medium

  * SECURITY UPDATE: Heap Buffer Overflow in AgileEngine
    - debian/patches/CVE-2026-4430.patch: Conform AlignEngine parsing to
      what section 2.3.4.10 of the spec has
    - CVE-2026-4430

 -- Rico Tzschichholz <email address hidden> Wed, 13 May 2026 09:44:03 +0200

Source diff to previous version
CVE-2026-4430 Out-of-bounds write vulnerability in The Document Foundation LibreOffice via crafted OOXML documents with mismatched encryption salt parameters. Thi

Version: 1:7.3.7-0ubuntu0.22.04.10 2025-05-08 19:07:39 UTC

  libreoffice (1:7.3.7-0ubuntu0.22.04.10) jammy-security; urgency=medium

  * SECURITY UPDATE: PDF signature forgery with adbe.pkcs7.sha1 SubFilter
    - debian/patches/CVE-2025-2866.patch: Improve adbe.pkcs7.sha1 signature
      verification
    - CVE-2025-2866

 -- Rico Tzschichholz <email address hidden> Mon, 05 May 2025 17:20:55 +0200

Source diff to previous version
CVE-2025-2866 Improper Verification of Cryptographic Signature vulnerability in LibreOffice allows PDF Signature Spoofing by Improper Validation. In the affect

Version: 1:7.3.7-0ubuntu0.22.04.9 2025-03-10 21:07:23 UTC

  libreoffice (1:7.3.7-0ubuntu0.22.04.9) jammy-security; urgency=medium

  * SECURITY UPDATE: Macro URL arbitrary script execution
    - debian/patches/CVE-2025-1080.patch: Filter out more unwanted command
      URIs
    - CVE-2025-1080

 -- Rico Tzschichholz <email address hidden> Thu, 06 Mar 2025 08:58:09 +0100

CVE-2025-1080 LibreOffice supports Office URI Schemes to enable browser integration of LibreOffice with MS SharePoint server. An additional scheme 'vnd.libreoffice



About   -   Send Feedback to @ubuntu_updates