Debian Security Advisory

DLA-591-1 libreoffice -- LTS security update

Date Reported:
09 Aug 2016
Affected Packages:
Security database references:
In Mitre's CVE dictionary: CVE-2016-1513.
More information:

An OpenDocument Presentation .ODP or Presentation Template .OTP file can contain invalid presentation elements that lead to memory corruption when the document is loaded in LibreOffice Impress. The defect may cause the document to appear as corrupted and LibreOffice may crash in a recovery-stuck mode requiring manual intervention. A crafted exploitation of the defect can allow an attacker to cause denial of service (memory corruption and application crash) and possible execution of arbitrary code.

For Debian 7 Wheezy, this problem have been fixed in version 3.5.4+dfsg2-0+deb7u8.

We recommend that you upgrade your libreoffice packages.

Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: