Debian Security Advisory
DSA-4022-1 libreoffice -- security update
- Date Reported:
- 07 Nov 2017
- Affected Packages:
- libreoffice
- Vulnerable:
- Yes
- Security database references:
- In Mitre's CVE dictionary: CVE-2017-12607, CVE-2017-12608.
- More information:
-
Marcin Noga discovered two vulnerabilities in LibreOffice, which could result in the execution of arbitrary code if a malformed PPT or DOC document is opened.
For the oldstable distribution (jessie), these problems have been fixed in version 1:4.3.3-2+deb8u9.
These vulnerabilities were fixed in Libreoffice 5.0.2, so the version in the stable distribution (stretch) is not affected.
We recommend that you upgrade your libreoffice packages.