Protect yourself against future threats.
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 =========================================================================== AUSCERT External Security Bulletin Redistribution ESB-2019.3130 libreoffice security update 16 August 2019 =========================================================================== AusCERT Security Bulletin Summary --------------------------------- Product: libreoffice Publisher: Debian Operating System: Debian GNU/Linux 9 Debian GNU/Linux 10 Impact/Access: Execute Arbitrary Code/Commands -- Remote with User Interaction Resolution: Patch/Upgrade CVE Names: CVE-2019-9852 CVE-2019-9851 CVE-2019-9850 Reference: ESB-2019.2691 ESB-2019.0350 ESB-2019.0305.2 Original Bulletin: http://www.debian.org/security/2019/dsa-4501 - --------------------------BEGIN INCLUDED TEXT-------------------- - -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - - ------------------------------------------------------------------------- Debian Security Advisory DSA-4501-1 security@debian.org https://www.debian.org/security/ Moritz Muehlenhoff August 15, 2019 https://www.debian.org/security/faq - - ------------------------------------------------------------------------- Package : libreoffice CVE ID : CVE-2019-9850 CVE-2019-9851 CVE-2019-9852 It was discovered that the code fixes to address CVE-2018-16858 and CVE-2019-9848 were not complete. For the oldstable distribution (stretch), these problems have been fixed in version 1:5.2.7-1+deb9u10. For the stable distribution (buster), these problems have been fixed in version 1:6.1.5-3+deb10u3. We recommend that you upgrade your libreoffice packages. For the detailed security status of libreoffice please refer to its security tracker page at: https://security-tracker.debian.org/tracker/libreoffice Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: debian-security-announce@lists.debian.org - -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEtuYvPRKsOElcDakFEMKTtsN8TjYFAl1VupsACgkQEMKTtsN8 Tja6Aw//TjIt4TReg1H4Wg3fMRCmBn8YusujHBl8QkYRa4XtbviN/UPXV7ck8N7p Bx/d+yc2Y1rYu0UgRWwYQPKpeyCiErY+lHUtP3X4OIkSWVPX/m3zW2bs7PS/+3DY aaTZduypXsJBvgP03dqERJl//2hSoUAjILn8aY1JplbLMjN/MSt1lqInKmdf9Y0m EmCWNcEiYbecDF4miKAUbKUdWr7UsysMS7wfJsydrTxBIgOt9A6mz4aqwPxGp7RS mnaSQXY8yBvkAN7Rk+LhMPTkI172QL4j1db+RXSjulVN8cgh2DTQ5leSMXG563qu 5RfAOrlf9q7T1dmcbBEAro6cafSLpR1PMYpC35aKeTc+w5HhsS32+4QRI173MyZ+ 3xBxlYVZzzXEMDpc0RXxZtzN1dv4BhvWrSBLURgd+ZSAVVbJscg9A9MiEdsPyiqA GEus2GCJmNo1fnBwD6Ok9mhyy+sSVsCl2eBK4is2xIjLJt+2JJuDQQ6vF3DSfzPa 1HbuLGrmuLS+6GONbqUKCdRKWjmX6SY416Sn3VpyJexELyUXilqGMpYLJal93wC+ A3lVexAhEFDvsPnmkqAbtaXep68UjbGwSSw6imieXdbYh0j7Ie4OREarBKcuGzQe wTqapvikvIM9hUDT9K9598B8GfJDmxKMSAydDVeUqQCxWxdM8IM= =Vlh7 - -----END PGP SIGNATURE----- - --------------------------END INCLUDED TEXT-------------------- You have received this e-mail bulletin as a result of your organisation's registration with AusCERT. The mailing list you are subscribed to is maintained within your organisation, so if you do not wish to continue receiving these bulletins you should contact your local IT manager. If you do not know who that is, please send an email to auscert@auscert.org.au and we will forward your request to the appropriate person. NOTE: Third Party Rights This security bulletin is provided as a service to AusCERT's members. As AusCERT did not write the document quoted above, AusCERT has had no control over its content. The decision to follow or act on information or advice contained in this security bulletin is the responsibility of each user or organisation, and should be considered in accordance with your organisation's site policies and procedures. AusCERT takes no responsibility for consequences which may arise from following or acting on information or advice contained in this security bulletin. NOTE: This is only the original release of the security bulletin. It may not be updated when updates to the original are made. If downloading at a later date, it is recommended that the bulletin is retrieved directly from the author's website to ensure that the information is still current. Contact information for the authors of the original document is included in the Security Bulletin above. If you have any questions or need further information, please contact them directly. Previous advisories and external security bulletins can be retrieved from: https://www.auscert.org.au/bulletins/ =========================================================================== Australian Computer Emergency Response Team The University of Queensland Brisbane Qld 4072 Internet Email: auscert@auscert.org.au Facsimile: (07) 3365 7031 Telephone: (07) 3365 4417 (International: +61 7 3365 4417) AusCERT personnel answer during Queensland business hours which are GMT+10:00 (AEST). On call after hours for member emergencies only. =========================================================================== -----BEGIN PGP SIGNATURE----- Comment: http://www.auscert.org.au/render.html?it=1967 iQIVAwUBXVXwVWaOgq3Tt24GAQjLOBAAsHbAQEhtnvDk8kpsZS1Ucu/fwW4Ozg/+ zev4Y9/GEa45ezgqRwxrtwI54MmigjGmu1bQ4fbfA471fGKQrOt/9ZYqI1cclC3+ BzdwMltznUQhtXBdXda4JMu/cThtFy4UFAs4UX9CGsj676svsDPb1JM2bNlhmvwZ Taw9bKb+1zftr/0yCmw+bcUWSYUhVGxjK8D6qTcTSO/7J2COfTzybHP5ER8mAAqt oefGN+1k7Lu/USQf4UVLf3M1X7KsOTVIOZ/7k+tXyrhrbLR8cZhoxpCh9H9M54Po 4DtUwBSJOGPMhJfrVfgi2fVBeBX/wZu+DPXXWihNFEX4Fzv9sosk578dmIlEeTqw rADDuWkVnRmrHzS8ddL+GMHbjcvpeMydJo2+aynwFHO8BLYfwcpIBsag4AcshDNx DG2MPcSOuJ3gNesiCB+wDBNNKlWD8mwJduL0kO6pjN1TgcrruLT9vZckfxI2GedY m7sfNASZ9EINS4k5u7X7PyyT1au1zDBk2gLidleOYdxSRX6efkkM/ofTUsN29HOU BJ4wwCkONNYsLCEQe2QH9EELX1tyD3ZYwkgMYt62QMl2I63KwbJ+umZCei+oi4fM dQCbsiS2qottiV/au49gK+B/Z45lUvXRItFIsOpVycSBxq3gIhYTDYJnIDSq8HtH qWM4tk6RacI= =8hVT -----END PGP SIGNATURE-----