{"id":"MGASA-2019-0102","summary":"Updated libreoffice packages fix security vulnerability","details":"Alex Infuehr discovered a directory traversal vulnerability which could\nresult in the execution of Python script code when opening a malformed\ndocument (CVE-2018-16858).\n\nThe libreoffice package has been updated to version 6.1.5.2, fixing this\nissue, and including several other bug fixes and enhancements.  Several\nsupporting library packages have been updated as well.\n\nHere's the list of improvements from 5.3 to 6.1:\nhttps://wiki.documentfoundation.org/ReleaseNotes/5.4\nhttps://wiki.documentfoundation.org/ReleaseNotes/6.0\nhttps://wiki.documentfoundation.org/ReleaseNotes/6.1\n","modified":"2026-04-16T04:42:54.106376677Z","published":"2019-02-22T01:08:50Z","upstream":["CVE-2018-16858"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2019-0102.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=24309"},{"type":"ADVISORY","url":"https://www.libreoffice.org/about-us/security/advisories/cve-2018-16858/"},{"type":"WEB","url":"https://www.debian.org/security/2019/dsa-4381"}],"affected":[{"package":{"name":"libabw","ecosystem":"Mageia:6","purl":"pkg:rpm/mageia/libabw?arch=source&distro=mageia-6"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.1.2-1.mga6"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2019-0102.json"}},{"package":{"name":"libcdr","ecosystem":"Mageia:6","purl":"pkg:rpm/mageia/libcdr?arch=source&distro=mageia-6"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.1.5-1.mga6"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2019-0102.json"}},{"package":{"name":"libcmis","ecosystem":"Mageia:6","purl":"pkg:rpm/mageia/libcmis?arch=source&distro=mageia-6"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.5.2-1.mga6"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2019-0102.json"}},{"package":{"name":"libe-book","ecosystem":"Mageia:6","purl":"pkg:rpm/mageia/libe-book?arch=source&distro=mageia-6"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.1.3-1.mga6"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2019-0102.json"}},{"package":{"name":"libetonyek","ecosystem":"Mageia:6","purl":"pkg:rpm/mageia/libetonyek?arch=source&distro=mageia-6"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.1.9-1.mga6"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2019-0102.json"}},{"package":{"name":"libfreehand","ecosystem":"Mageia:6","purl":"pkg:rpm/mageia/libfreehand?arch=source&distro=mageia-6"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.1.2-2.mga6"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2019-0102.json"}},{"package":{"name":"libmspub","ecosystem":"Mageia:6","purl":"pkg:rpm/mageia/libmspub?arch=source&distro=mageia-6"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.1.4-1.mga6"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2019-0102.json"}},{"package":{"name":"libmwaw","ecosystem":"Mageia:6","purl":"pkg:rpm/mageia/libmwaw?arch=source&distro=mageia-6"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.3.14-2.mga6"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2019-0102.json"}},{"package":{"name":"libodfgen","ecosystem":"Mageia:6","purl":"pkg:rpm/mageia/libodfgen?arch=source&distro=mageia-6"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.1.7-1.mga6"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2019-0102.json"}},{"package":{"name":"libpagemaker","ecosystem":"Mageia:6","purl":"pkg:rpm/mageia/libpagemaker?arch=source&distro=mageia-6"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.0.4-1.mga6"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2019-0102.json"}},{"package":{"name":"libstaroffice","ecosystem":"Mageia:6","purl":"pkg:rpm/mageia/libstaroffice?arch=source&distro=mageia-6"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.0.6-1.mga6"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2019-0102.json"}},{"package":{"name":"libvisio","ecosystem":"Mageia:6","purl":"pkg:rpm/mageia/libvisio?arch=source&distro=mageia-6"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.1.6-1.mga6"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2019-0102.json"}},{"package":{"name":"libwpg","ecosystem":"Mageia:6","purl":"pkg:rpm/mageia/libwpg?arch=source&distro=mageia-6"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.3.3-1.mga6"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2019-0102.json"}},{"package":{"name":"libwps","ecosystem":"Mageia:6","purl":"pkg:rpm/mageia/libwps?arch=source&distro=mageia-6"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.4.10-1.mga6"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2019-0102.json"}},{"package":{"name":"libzmf","ecosystem":"Mageia:6","purl":"pkg:rpm/mageia/libzmf?arch=source&distro=mageia-6"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.0.2-1.mga6"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2019-0102.json"}},{"package":{"name":"cppunit","ecosystem":"Mageia:6","purl":"pkg:rpm/mageia/cppunit?arch=source&distro=mageia-6"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.14.0-1.mga6"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2019-0102.json"}},{"package":{"name":"libepubgen","ecosystem":"Mageia:6","purl":"pkg:rpm/mageia/libepubgen?arch=source&distro=mageia-6"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.1.1-2.mga6"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2019-0102.json"}},{"package":{"name":"libixion","ecosystem":"Mageia:6","purl":"pkg:rpm/mageia/libixion?arch=source&distro=mageia-6"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.14.1-1.mga6"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2019-0102.json"}},{"package":{"name":"libnumbertext","ecosystem":"Mageia:6","purl":"pkg:rpm/mageia/libnumbertext?arch=source&distro=mageia-6"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.0.5-1.mga6"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2019-0102.json"}},{"package":{"name":"liborcus","ecosystem":"Mageia:6","purl":"pkg:rpm/mageia/liborcus?arch=source&distro=mageia-6"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.14.1-1.mga6"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2019-0102.json"}},{"package":{"name":"libqxp","ecosystem":"Mageia:6","purl":"pkg:rpm/mageia/libqxp?arch=source&distro=mageia-6"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.0.2-1.mga6"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2019-0102.json"}},{"package":{"name":"mdds","ecosystem":"Mageia:6","purl":"pkg:rpm/mageia/mdds?arch=source&distro=mageia-6"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.4.3-1.mga6"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2019-0102.json"}},{"package":{"name":"libreoffice","ecosystem":"Mageia:6","purl":"pkg:rpm/mageia/libreoffice?arch=source&distro=mageia-6"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.1.5.2-1.2.mga6"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2019-0102.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}