Debian Security Advisory

DSA-3236-1 libreoffice -- security update

Date Reported:
25 Apr 2015
Affected Packages:
libreoffice
Vulnerable:
Yes
Security database references:
In Mitre's CVE dictionary: CVE-2015-1774.
More information:

It was discovered that missing input sanitising in Libreoffice's filter for HWP documents may result in the execution of arbitrary code if a malformed document is opened.

For the oldstable distribution (wheezy), this problem has been fixed in version 1:3.5.4+dfsg2-0+deb7u4.

For the stable distribution (jessie), this problem has been fixed in version 1:4.3.3-2+deb8u1.

For the unstable distribution (sid), this problem will be fixed soon.

We recommend that you upgrade your libreoffice packages.