{"id":"MGASA-2024-0209","summary":"Updated libreoffice packages fix security vulnerability","details":"Unchecked script execution in Graphic on-click binding in affected\nLibreOffice versions allows an attacker to create a document which\nwithout prompt will execute scripts built-into LibreOffice on clicking a\ngraphic. Such scripts were previously deemed trusted but are now deemed\nuntrusted. (CVE-2024-3044)\n","modified":"2026-04-16T04:43:14.299952072Z","published":"2024-06-03T18:30:48Z","upstream":["CVE-2024-3044"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2024-0209.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=33222"},{"type":"WEB","url":"https://lwn.net/Articles/973885/"}],"affected":[{"package":{"name":"libreoffice","ecosystem":"Mageia:9","purl":"pkg:rpm/mageia/libreoffice?arch=source&distro=mageia-9"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"7.6.7.2-1.mga9"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2024-0209.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}