{"id":"ECHO-0c5b-b878-d4d7","summary":"Not a vulnerability in LibreOffice itself. The report is that documents\ncan embed or link external content that LibreOffice opens automatically,\nwhich is documented, expected behaviour of the OpenDocument format rather\nthan a memory-safety or logic bug. Upstream treated it as a UI/hardening\nimprovement request (fdo#58295). Debian classifies it as unimportant\n(\"Additional hardening/UI improvement, not a direct vulnerability\") and\nhas left it unfixed in every release. No code change is required.\n\nhttps://security-tracker.debian.org/tracker/CVE-2012-5639\n","modified":"2026-09-29T11:45:37.713904076Z","published":"2026-04-20T21:16:23.369120Z","withdrawn":"2026-09-29T11:00:03.921Z","upstream":["CVE-2012-5639"],"references":[{"type":"WEB","url":"https://advisory.echohq.com/cve/CVE-2012-5639"}],"affected":[{"package":{"name":"libreoffice","ecosystem":"Echo","purl":"pkg:deb/echo/libreoffice"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4:25.2.3-2+deb13u6"}]}],"database_specific":{"source":"https://advisory.echohq.com/osv/ECHO-0c5b-b878-d4d7.json"}}],"schema_version":"1.9.0"}