USN-2398-1: LibreOffice vulnerability
5 November 2014
LibreOffice could be made to crash or run programs if it received specially crafted network traffic.
Releases
Packages
- libreoffice - Office productivity suite
Details
It was discovered that LibreOffice incorrectly handled the Impress remote
control port. An attacker could possibly use this issue to cause Impress to
crash, resulting in a denial of service, or possibly execute arbitrary
code.
Update instructions
The problem can be corrected by updating your system to the following package versions:
Ubuntu 14.10
Ubuntu 14.04
This update uses a new upstream release, which includes additional bug
fixes. After a standard system update you need to restart LibreOffice to
make all the necessary changes.