UbuntuUpdates.org

Package "libuno-cppu3t64"

Name: libuno-cppu3t64

Description:

LibreOffice UNO runtime environment -- CPPU public library

Latest version: 4:26.2.6.3-0ubuntu0.26.04.2
Release: resolute (26.04)
Level: security
Repository: main
Head package: libreoffice
Homepage: http://www.libreoffice.org

Links


Download "libuno-cppu3t64"


Other versions of "libuno-cppu3t64" in Resolute

Repository Area Version
base main 4:26.2.2.2-0ubuntu1
updates main 4:26.2.6.3-0ubuntu0.26.04.2
proposed main 4:26.2.6.3-0ubuntu0.26.04.1
PPA: LibreOffice 4:26.2.6.3-0ubuntu0.26.04.1~lo1

Changelog

Version: 4:26.2.6.3-0ubuntu0.26.04.2 2026-10-07 15:39:03 UTC

libreoffice (4:26.2.6.3-0ubuntu0.26.04.2) resolute-security; urgency=medium

  * No-change rebuild in the -security pocket.
  * SECURITY UPDATE: Heap buffer overflow in WMF text record import
    - CVE-2026-63272
  * SECURITY UPDATE: Heap buffer overflow in PDF import encryption handling
    - CVE-2026-63273
  * SECURITY UPDATE: Heap buffer overflow in PDF import stream handling
    - CVE-2026-63274
  * SECURITY UPDATE: Stack buffer overflow in CFF font hint handling
    - CVE-2026-63275
  * SECURITY UPDATE: Stack buffer overflow in CFF to Type 1 font conversion
    - CVE-2026-63276
  * SECURITY UPDATE: Package URLs can be used to exfiltrate arbitrary INI
    file values and environment variables
    - CVE-2026-63278
  * SECURITY UPDATE: Out of bounds read in PICT image import
    - CVE-2026-63279

 -- Rico Tzschichholz Mon, 28 Sep 2026 10:35:32 +0200

Source diff to previous version
CVE-2026-63272 LibreOffice can import WMF graphics, which may be embedded in documents. A heap buffer overflow existed when importing a text record that carries its
CVE-2026-63273 LibreOffice Draw can import PDF documents. A heap buffer overflow existed when importing an encrypted document. The length of the decryption key was
CVE-2026-63274 LibreOffice Draw can import PDF documents. A heap buffer overflow existed when importing a stream object. The length of the stream was taken from the
CVE-2026-63275 LibreOffice can read CFF fonts, which may be embedded in documents. A stack buffer overflow existed when reading the hints of a glyph. The number of
CVE-2026-63276 LibreOffice converts CFF fonts to Type 1 when it subsets a font, which happens when a document is exported to PDF, and CFF fonts may be embedded in d
CVE-2026-63278 URLs could be constructed which expanded environment variable or INI file values, so potentially sensitive information could be exfiltrated to a remo
CVE-2026-63279 LibreOffice can import PICT images, which may be embedded in documents. An out of bounds read existed when importing an image that uses a colour pale

Version: 4:26.2.4.2-0ubuntu0.26.04.2 2026-07-13 21:09:43 UTC

  libreoffice (4:26.2.4.2-0ubuntu0.26.04.2) resolute-security; urgency=medium

  * No-change rebuild in the -security pocket.
  * SECURITY UPDATE: Stack buffer overflow in PPT presentation import
    - CVE-2026-8356
  * SECURITY UPDATE: Heap buffer overflow in Calc formula compilation
    - CVE-2026-8357
  * SECURITY UPDATE: Heap buffer overflow in spreadsheet tracked-changes import
    - CVE-2026-8358

 -- Rico Tzschichholz <email address hidden> Sun, 28 Jun 2026 12:36:00 +0200

Source diff to previous version
CVE-2026-8356 LibreOffice can import presentations in the legacy binary PPT format. A stack buffer overflow existed when importing a colour-replacement record. Two
CVE-2026-8357 LibreOffice Calc compiles cell formulas when opening a spreadsheet. A heap buffer overflow existed when compiling a very long formula made up of many
CVE-2026-8358 LibreOffice Calc can import tracked changes from a spreadsheet document. A heap buffer overflow existed when a document reused the same change identi

Version: 4:26.2.3.2-0ubuntu0.26.04.1 2026-06-01 16:07:38 UTC

  libreoffice (4:26.2.3.2-0ubuntu0.26.04.1) resolute-security; urgency=medium

  * New upstream release (LP: #2150525)
  * SECURITY UPDATE: Heap Buffer Overflow in AgileEngine
    - CVE-2026-4430

 -- Rico Tzschichholz <email address hidden> Mon, 27 Apr 2026 08:21:09 +0200

2150525 [SRU] libreoffice 26.2.3 for resolute
CVE-2026-4430 Out-of-bounds write vulnerability in The Document Foundation LibreOffice via crafted OOXML documents with mismatched encryption salt parameters. Thi



About   -   Send Feedback to @ubuntu_updates