{"id":"RLSA-2023:0304","summary":"Moderate: libreoffice security update","details":"LibreOffice is an open source, community-developed office productivity suite. It includes key desktop applications, such as a word processor, a spreadsheet, a presentation manager, a formula editor, and a drawing program. LibreOffice replaces OpenOffice and provides a similar but enhanced and extended office suite.\n\nSecurity Fix(es):\n\n* libreoffice: Macro URL arbitrary script execution (CVE-2022-3140)\n\n* libreoffice: Execution of Untrusted Macros Due to Improper Certificate Validation (CVE-2022-26305)\n\n* libreoffice: Static Initialization Vector Allows to Recover Passwords for Web Connections Without Knowing the Master Password (CVE-2022-26306)\n\n* libreoffice: Weak Master Keys (CVE-2022-26307)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.","modified":"2026-02-04T08:30:16.300963Z","published":"2023-01-23T14:29:58Z","upstream":["CVE-2022-26305","CVE-2022-26306","CVE-2022-26307","CVE-2022-3140"],"references":[{"type":"ADVISORY","url":"https://errata.rockylinux.org/RLSA-2023:0304"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2118610"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2118611"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2118613"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2134697"}],"affected":[{"package":{"name":"libreoffice","ecosystem":"Rocky Linux:9","purl":"pkg:rpm/rocky-linux/libreoffice?distro=rocky-linux-9&epoch=1"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1:7.1.8.1-8.el9_1"}],"database_specific":{"yum_repository":"AppStream"}}],"database_specific":{"source":"https://storage.googleapis.com/resf-osv-data/RLSA-2023:0304.json"}}],"schema_version":"1.7.3","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}],"credits":[{"name":"Rocky Enterprise Software Foundation"},{"name":"Red Hat"}]}