Re: [BLFS Trac] #23238: libreoffice-26.2.4.1

"BLFS Trac" ([email protected] via blfs-book Mailing List) <[email protected]>
Newsgroups gmane.linux.lfs.beyond.book
Message-ID <[email protected]>
#23238: libreoffice-26.2.4.1
-------------------------+------------------------------
 Reporter:  Bruce Dubbs  |       Owner:  Douglas R. Reno
     Type:  enhancement  |      Status:  assigned
 Priority:  elevated     |   Milestone:  13.1
Component:  BOOK         |     Version:  git
 Severity:  normal       |  Resolution:
 Keywords:               |
-------------------------+------------------------------
Changes (by Douglas R. Reno):

 * priority:  normal => elevated

Comment:

 There should be a new version tomorrow.

 In the meantime, I must report a security issue:

 {{{
 CVE-2026-4430 Heap Buffer Overflow in AgileEngine

 Announced: May 06, 2026

 Fixed in: LibreOffice 26.2.3 and LibreOffice 25.8.7

 Description:

 Out-of-bounds write vulnerability in The Document Foundation LibreOffice
 via crafted
 OOXML documents with mismatched encryption salt parameters.

 This issue affects LibreOffice: from 26.2 before 26.2.3, from 25.8 before
 25.8.7.

 Credits:

 Thanks to Duc Anh Nguyen (@Danzation) for finding and reporting this
 issue.

 Thanks to Caolán McNamara of Collabora Productivity for providing a fix.

 References:

 CVE-2026-4430
 }}}

 This is rated as Medium, so to Elevated it goes
-- 
Ticket URL: <https://wiki.linuxfromscratch.org/blfs/ticket/23238#comment:7>
BLFS Trac <https://wiki.linuxfromscratch.org/blfs/>
Beyond Linux From Scratch

-- 
http://lists.linuxfromscratch.org/sympa/info/blfs-book
Unsubscribe: See the above information page
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.