Bug 17097 - [update candidate] libreoffice 4.4.6
Summary: [update candidate] libreoffice 4.4.6
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 5
Hardware: All Linux
Priority: Normal major
Target Milestone: ---
Assignee: QA Team
QA Contact:
URL: http://lwn.net/Vulnerabilities/663512/
Whiteboard: mga5-32-ok mga5-64-ok advisory
Keywords: validated_update
Depends on:
Blocks:
 
Reported: 2015-11-06 09:42 CET by Thierry Vignaud
Modified: 2015-11-10 22:27 CET (History)
4 users (show)

See Also:
Source RPM: libreoffice-4.4.6.3-2.2.mga5.src.rpm
CVE:
Status comment:


Attachments

Description Thierry Vignaud 2015-11-06 09:42:48 CET
Advisory:
==========
This updates libreoffice from 4.4.2 to 4.4.6, which is a pure bug fixes release.

For details, see:
http://download.documentfoundation.org/libreoffice/src/bugs-changelog-libreoffice-4-4-4-release-4.4.4.1.log
http://download.documentfoundation.org/libreoffice/src/bugs-changelog-libreoffice-4-4-4-release-4.4.4.2.log
http://download.documentfoundation.org/libreoffice/src/bugs-changelog-libreoffice-4-4-4-release-4.4.4.3.log
http://download.documentfoundation.org/libreoffice/src/bugs-changelog-libreoffice-4-4-5-release-4.4.5.1.log
http://download.documentfoundation.org/libreoffice/src/bugs-changelog-libreoffice-4-4-5-release-4.4.5.2.log
http://download.documentfoundation.org/libreoffice/src/bugs-changelog-libreoffice-4-4-6-release-4.4.6.1.log
http://download.documentfoundation.org/libreoffice/src/bugs-changelog-libreoffice-4-4-6-release-4.4.6.2.log
http://download.documentfoundation.org/libreoffice/src/bugs-changelog-libreoffice-4-4-6-release-4.4.6.3.log


Package list:
=============

Here's the package list (for 32 bit):
(from http://sophie.zarb.org/rpms/560e8e1ee2359915aa7ade691f6c8d19)

libreoffice-4.4.6.3-2.2.mga5.i586.rpm
libreoffice-base-4.4.6.3-2.2.mga5.i586.rpm
libreoffice-bsh-4.4.6.3-2.2.mga5.i586.rpm
libreoffice-calc-4.4.6.3-2.2.mga5.i586.rpm
libreoffice-core-4.4.6.3-2.2.mga5.i586.rpm
libreoffice-draw-4.4.6.3-2.2.mga5.i586.rpm
libreoffice-emailmerge-4.4.6.3-2.2.mga5.i586.rpm
libreoffice-filters-4.4.6.3-2.2.mga5.i586.rpm
libreoffice-glade-4.4.6.3-2.2.mga5.i586.rpm
libreoffice-graphicfilter-4.4.6.3-2.2.mga5.i586.rpm
libreoffice-impress-4.4.6.3-2.2.mga5.i586.rpm
libreoffice-java-common-4.4.6.3-2.2.mga5.i586.rpm
libreoffice-kde-4.4.6.3-2.2.mga5.i586.rpm
libreoffice-langpack-af-4.4.6.3-2.2.mga5.i586.rpm
libreoffice-langpack-ar-4.4.6.3-2.2.mga5.i586.rpm
libreoffice-langpack-as-4.4.6.3-2.2.mga5.i586.rpm
libreoffice-langpack-bg-4.4.6.3-2.2.mga5.i586.rpm
libreoffice-langpack-bn-4.4.6.3-2.2.mga5.i586.rpm
libreoffice-langpack-br-4.4.6.3-2.2.mga5.i586.rpm
libreoffice-langpack-ca-4.4.6.3-2.2.mga5.i586.rpm
libreoffice-langpack-cs-4.4.6.3-2.2.mga5.i586.rpm
libreoffice-langpack-cy-4.4.6.3-2.2.mga5.i586.rpm
libreoffice-langpack-da-4.4.6.3-2.2.mga5.i586.rpm
libreoffice-langpack-de-4.4.6.3-2.2.mga5.i586.rpm
libreoffice-langpack-dz-4.4.6.3-2.2.mga5.i586.rpm
libreoffice-langpack-el-4.4.6.3-2.2.mga5.i586.rpm
libreoffice-langpack-en-4.4.6.3-2.2.mga5.i586.rpm
libreoffice-langpack-es-4.4.6.3-2.2.mga5.i586.rpm
libreoffice-langpack-et-4.4.6.3-2.2.mga5.i586.rpm
libreoffice-langpack-eu-4.4.6.3-2.2.mga5.i586.rpm
libreoffice-langpack-fa-4.4.6.3-2.2.mga5.i586.rpm
libreoffice-langpack-fi-4.4.6.3-2.2.mga5.i586.rpm
libreoffice-langpack-fr-4.4.6.3-2.2.mga5.i586.rpm
libreoffice-langpack-ga-4.4.6.3-2.2.mga5.i586.rpm
libreoffice-langpack-gl-4.4.6.3-2.2.mga5.i586.rpm
libreoffice-langpack-gu-4.4.6.3-2.2.mga5.i586.rpm
libreoffice-langpack-he-4.4.6.3-2.2.mga5.i586.rpm
libreoffice-langpack-hi-4.4.6.3-2.2.mga5.i586.rpm
libreoffice-langpack-hr-4.4.6.3-2.2.mga5.i586.rpm
libreoffice-langpack-hu-4.4.6.3-2.2.mga5.i586.rpm
libreoffice-langpack-it-4.4.6.3-2.2.mga5.i586.rpm
libreoffice-langpack-ja-4.4.6.3-2.2.mga5.i586.rpm
libreoffice-langpack-kk-4.4.6.3-2.2.mga5.i586.rpm
libreoffice-langpack-kn-4.4.6.3-2.2.mga5.i586.rpm
libreoffice-langpack-ko-4.4.6.3-2.2.mga5.i586.rpm
libreoffice-langpack-lt-4.4.6.3-2.2.mga5.i586.rpm
libreoffice-langpack-lv-4.4.6.3-2.2.mga5.i586.rpm
libreoffice-langpack-mai-4.4.6.3-2.2.mga5.i586.rpm
libreoffice-langpack-ml-4.4.6.3-2.2.mga5.i586.rpm
libreoffice-langpack-mr-4.4.6.3-2.2.mga5.i586.rpm
libreoffice-langpack-nb-4.4.6.3-2.2.mga5.i586.rpm
libreoffice-langpack-nl-4.4.6.3-2.2.mga5.i586.rpm
libreoffice-langpack-nn-4.4.6.3-2.2.mga5.i586.rpm
libreoffice-langpack-nr-4.4.6.3-2.2.mga5.i586.rpm
libreoffice-langpack-nso-4.4.6.3-2.2.mga5.i586.rpm
libreoffice-langpack-or-4.4.6.3-2.2.mga5.i586.rpm
libreoffice-langpack-pa-4.4.6.3-2.2.mga5.i586.rpm
libreoffice-langpack-pl-4.4.6.3-2.2.mga5.i586.rpm
libreoffice-langpack-pt-4.4.6.3-2.2.mga5.i586.rpm
libreoffice-langpack-pt_BR-4.4.6.3-2.2.mga5.i586.rpm
libreoffice-langpack-ro-4.4.6.3-2.2.mga5.i586.rpm
libreoffice-langpack-ru-4.4.6.3-2.2.mga5.i586.rpm
libreoffice-langpack-si-4.4.6.3-2.2.mga5.i586.rpm
libreoffice-langpack-sk-4.4.6.3-2.2.mga5.i586.rpm
libreoffice-langpack-sl-4.4.6.3-2.2.mga5.i586.rpm
libreoffice-langpack-sr-4.4.6.3-2.2.mga5.i586.rpm
libreoffice-langpack-ss-4.4.6.3-2.2.mga5.i586.rpm
libreoffice-langpack-st-4.4.6.3-2.2.mga5.i586.rpm
libreoffice-langpack-sv-4.4.6.3-2.2.mga5.i586.rpm
libreoffice-langpack-ta-4.4.6.3-2.2.mga5.i586.rpm
libreoffice-langpack-te-4.4.6.3-2.2.mga5.i586.rpm
libreoffice-langpack-th-4.4.6.3-2.2.mga5.i586.rpm
libreoffice-langpack-tn-4.4.6.3-2.2.mga5.i586.rpm
libreoffice-langpack-tr-4.4.6.3-2.2.mga5.i586.rpm
libreoffice-langpack-ts-4.4.6.3-2.2.mga5.i586.rpm
libreoffice-langpack-uk-4.4.6.3-2.2.mga5.i586.rpm
libreoffice-langpack-ve-4.4.6.3-2.2.mga5.i586.rpm
libreoffice-langpack-xh-4.4.6.3-2.2.mga5.i586.rpm
libreoffice-langpack-zh_CN-4.4.6.3-2.2.mga5.i586.rpm
libreoffice-langpack-zh_TW-4.4.6.3-2.2.mga5.i586.rpm
libreoffice-langpack-zu-4.4.6.3-2.2.mga5.i586.rpm
libreoffice-librelogo-4.4.6.3-2.2.mga5.i586.rpm
libreoffice-math-4.4.6.3-2.2.mga5.i586.rpm
libreoffice-nlpsolver-4.4.6.3-2.2.mga5.i586.rpm
libreoffice-officebean-4.4.6.3-2.2.mga5.i586.rpm
libreoffice-ogltrans-4.4.6.3-2.2.mga5.i586.rpm
libreoffice-pdfimport-4.4.6.3-2.2.mga5.i586.rpm
libreoffice-postgresql-4.4.6.3-2.2.mga5.i586.rpm
libreoffice-pyuno-4.4.6.3-2.2.mga5.i586.rpm
libreoffice-rhino-4.4.6.3-2.2.mga5.i586.rpm
libreoffice-sdk-4.4.6.3-2.2.mga5.i586.rpm
libreoffice-sdk-doc-4.4.6.3-2.2.mga5.i586.rpm
libreoffice-ure-4.4.6.3-2.2.mga5.i586.rpm
libreoffice-wiki-publisher-4.4.6.3-2.2.mga5.i586.rpm
libreoffice-writer-4.4.6.3-2.2.mga5.i586.rpm
libreoffice-xsltfilter-4.4.6.3-2.2.mga5.i586.rpm
autocorr-af-4.4.6.3-2.2.mga5.noarch.rpm
autocorr-bg-4.4.6.3-2.2.mga5.noarch.rpm
autocorr-ca-4.4.6.3-2.2.mga5.noarch.rpm
autocorr-cs-4.4.6.3-2.2.mga5.noarch.rpm
autocorr-da-4.4.6.3-2.2.mga5.noarch.rpm
autocorr-de-4.4.6.3-2.2.mga5.noarch.rpm
autocorr-en-4.4.6.3-2.2.mga5.noarch.rpm
autocorr-es-4.4.6.3-2.2.mga5.noarch.rpm
autocorr-fa-4.4.6.3-2.2.mga5.noarch.rpm
autocorr-fi-4.4.6.3-2.2.mga5.noarch.rpm
autocorr-fr-4.4.6.3-2.2.mga5.noarch.rpm
autocorr-ga-4.4.6.3-2.2.mga5.noarch.rpm
autocorr-hr-4.4.6.3-2.2.mga5.noarch.rpm
autocorr-hu-4.4.6.3-2.2.mga5.noarch.rpm
autocorr-is-4.4.6.3-2.2.mga5.noarch.rpm
autocorr-it-4.4.6.3-2.2.mga5.noarch.rpm
autocorr-ja-4.4.6.3-2.2.mga5.noarch.rpm
autocorr-ko-4.4.6.3-2.2.mga5.noarch.rpm
autocorr-lb-4.4.6.3-2.2.mga5.noarch.rpm
autocorr-lt-4.4.6.3-2.2.mga5.noarch.rpm
autocorr-mn-4.4.6.3-2.2.mga5.noarch.rpm
autocorr-nl-4.4.6.3-2.2.mga5.noarch.rpm
autocorr-pl-4.4.6.3-2.2.mga5.noarch.rpm
autocorr-pt-4.4.6.3-2.2.mga5.noarch.rpm
autocorr-ro-4.4.6.3-2.2.mga5.noarch.rpm
autocorr-ru-4.4.6.3-2.2.mga5.noarch.rpm
autocorr-sk-4.4.6.3-2.2.mga5.noarch.rpm
autocorr-sl-4.4.6.3-2.2.mga5.noarch.rpm
autocorr-sr-4.4.6.3-2.2.mga5.noarch.rpm
autocorr-sv-4.4.6.3-2.2.mga5.noarch.rpm
autocorr-tr-4.4.6.3-2.2.mga5.noarch.rpm
autocorr-vi-4.4.6.3-2.2.mga5.noarch.rpm
autocorr-zh-4.4.6.3-2.2.mga5.noarch.rpm
libreoffice-opensymbol-fonts-4.4.6.3-2.2.mga5.noarch.rpm
libreoffice-4.4.6.3-2.2.mga5.x86_64.rpm
libreoffice-base-4.4.6.3-2.2.mga5.x86_64.rpm
libreoffice-bsh-4.4.6.3-2.2.mga5.x86_64.rpm
libreoffice-calc-4.4.6.3-2.2.mga5.x86_64.rpm
libreoffice-core-4.4.6.3-2.2.mga5.x86_64.rpm
libreoffice-draw-4.4.6.3-2.2.mga5.x86_64.rpm
libreoffice-emailmerge-4.4.6.3-2.2.mga5.x86_64.rpm
libreoffice-filters-4.4.6.3-2.2.mga5.x86_64.rpm
libreoffice-glade-4.4.6.3-2.2.mga5.x86_64.rpm
libreoffice-graphicfilter-4.4.6.3-2.2.mga5.x86_64.rpm
libreoffice-impress-4.4.6.3-2.2.mga5.x86_64.rpm
libreoffice-java-common-4.4.6.3-2.2.mga5.x86_64.rpm
libreoffice-kde-4.4.6.3-2.2.mga5.x86_64.rpm
libreoffice-langpack-af-4.4.6.3-2.2.mga5.x86_64.rpm
libreoffice-langpack-ar-4.4.6.3-2.2.mga5.x86_64.rpm
libreoffice-langpack-as-4.4.6.3-2.2.mga5.x86_64.rpm
libreoffice-langpack-bg-4.4.6.3-2.2.mga5.x86_64.rpm
libreoffice-langpack-bn-4.4.6.3-2.2.mga5.x86_64.rpm
libreoffice-langpack-br-4.4.6.3-2.2.mga5.x86_64.rpm
libreoffice-langpack-ca-4.4.6.3-2.2.mga5.x86_64.rpm
libreoffice-langpack-cs-4.4.6.3-2.2.mga5.x86_64.rpm
libreoffice-langpack-cy-4.4.6.3-2.2.mga5.x86_64.rpm
libreoffice-langpack-da-4.4.6.3-2.2.mga5.x86_64.rpm
libreoffice-langpack-de-4.4.6.3-2.2.mga5.x86_64.rpm
libreoffice-langpack-dz-4.4.6.3-2.2.mga5.x86_64.rpm
libreoffice-langpack-el-4.4.6.3-2.2.mga5.x86_64.rpm
libreoffice-langpack-en-4.4.6.3-2.2.mga5.x86_64.rpm
libreoffice-langpack-es-4.4.6.3-2.2.mga5.x86_64.rpm
libreoffice-langpack-et-4.4.6.3-2.2.mga5.x86_64.rpm
libreoffice-langpack-eu-4.4.6.3-2.2.mga5.x86_64.rpm
libreoffice-langpack-fa-4.4.6.3-2.2.mga5.x86_64.rpm
libreoffice-langpack-fi-4.4.6.3-2.2.mga5.x86_64.rpm
libreoffice-langpack-fr-4.4.6.3-2.2.mga5.x86_64.rpm
libreoffice-langpack-ga-4.4.6.3-2.2.mga5.x86_64.rpm
libreoffice-langpack-gl-4.4.6.3-2.2.mga5.x86_64.rpm
libreoffice-langpack-gu-4.4.6.3-2.2.mga5.x86_64.rpm
libreoffice-langpack-he-4.4.6.3-2.2.mga5.x86_64.rpm
libreoffice-langpack-hi-4.4.6.3-2.2.mga5.x86_64.rpm
libreoffice-langpack-hr-4.4.6.3-2.2.mga5.x86_64.rpm
libreoffice-langpack-hu-4.4.6.3-2.2.mga5.x86_64.rpm
libreoffice-langpack-it-4.4.6.3-2.2.mga5.x86_64.rpm
libreoffice-langpack-ja-4.4.6.3-2.2.mga5.x86_64.rpm
libreoffice-langpack-kk-4.4.6.3-2.2.mga5.x86_64.rpm
libreoffice-langpack-kn-4.4.6.3-2.2.mga5.x86_64.rpm
libreoffice-langpack-ko-4.4.6.3-2.2.mga5.x86_64.rpm
libreoffice-langpack-lt-4.4.6.3-2.2.mga5.x86_64.rpm
libreoffice-langpack-lv-4.4.6.3-2.2.mga5.x86_64.rpm
libreoffice-langpack-mai-4.4.6.3-2.2.mga5.x86_64.rpm
libreoffice-langpack-ml-4.4.6.3-2.2.mga5.x86_64.rpm
libreoffice-langpack-mr-4.4.6.3-2.2.mga5.x86_64.rpm
libreoffice-langpack-nb-4.4.6.3-2.2.mga5.x86_64.rpm
libreoffice-langpack-nl-4.4.6.3-2.2.mga5.x86_64.rpm
libreoffice-langpack-nn-4.4.6.3-2.2.mga5.x86_64.rpm
libreoffice-langpack-nr-4.4.6.3-2.2.mga5.x86_64.rpm
libreoffice-langpack-nso-4.4.6.3-2.2.mga5.x86_64.rpm
libreoffice-langpack-or-4.4.6.3-2.2.mga5.x86_64.rpm
libreoffice-langpack-pa-4.4.6.3-2.2.mga5.x86_64.rpm
libreoffice-langpack-pl-4.4.6.3-2.2.mga5.x86_64.rpm
libreoffice-langpack-pt-4.4.6.3-2.2.mga5.x86_64.rpm
libreoffice-langpack-pt_BR-4.4.6.3-2.2.mga5.x86_64.rpm
libreoffice-langpack-ro-4.4.6.3-2.2.mga5.x86_64.rpm
libreoffice-langpack-ru-4.4.6.3-2.2.mga5.x86_64.rpm
libreoffice-langpack-si-4.4.6.3-2.2.mga5.x86_64.rpm
libreoffice-langpack-sk-4.4.6.3-2.2.mga5.x86_64.rpm
libreoffice-langpack-sl-4.4.6.3-2.2.mga5.x86_64.rpm
libreoffice-langpack-sr-4.4.6.3-2.2.mga5.x86_64.rpm
libreoffice-langpack-ss-4.4.6.3-2.2.mga5.x86_64.rpm
libreoffice-langpack-st-4.4.6.3-2.2.mga5.x86_64.rpm
libreoffice-langpack-sv-4.4.6.3-2.2.mga5.x86_64.rpm
libreoffice-langpack-ta-4.4.6.3-2.2.mga5.x86_64.rpm
libreoffice-langpack-te-4.4.6.3-2.2.mga5.x86_64.rpm
libreoffice-langpack-th-4.4.6.3-2.2.mga5.x86_64.rpm
libreoffice-langpack-tn-4.4.6.3-2.2.mga5.x86_64.rpm
libreoffice-langpack-tr-4.4.6.3-2.2.mga5.x86_64.rpm
libreoffice-langpack-ts-4.4.6.3-2.2.mga5.x86_64.rpm
libreoffice-langpack-uk-4.4.6.3-2.2.mga5.x86_64.rpm
libreoffice-langpack-ve-4.4.6.3-2.2.mga5.x86_64.rpm
libreoffice-langpack-xh-4.4.6.3-2.2.mga5.x86_64.rpm
libreoffice-langpack-zh_CN-4.4.6.3-2.2.mga5.x86_64.rpm
libreoffice-langpack-zh_TW-4.4.6.3-2.2.mga5.x86_64.rpm
libreoffice-langpack-zu-4.4.6.3-2.2.mga5.x86_64.rpm
libreoffice-librelogo-4.4.6.3-2.2.mga5.x86_64.rpm
libreoffice-math-4.4.6.3-2.2.mga5.x86_64.rpm
libreoffice-nlpsolver-4.4.6.3-2.2.mga5.x86_64.rpm
libreoffice-officebean-4.4.6.3-2.2.mga5.x86_64.rpm
libreoffice-ogltrans-4.4.6.3-2.2.mga5.x86_64.rpm
libreoffice-pdfimport-4.4.6.3-2.2.mga5.x86_64.rpm
libreoffice-postgresql-4.4.6.3-2.2.mga5.x86_64.rpm
libreoffice-pyuno-4.4.6.3-2.2.mga5.x86_64.rpm
libreoffice-rhino-4.4.6.3-2.2.mga5.x86_64.rpm
libreoffice-sdk-4.4.6.3-2.2.mga5.x86_64.rpm
libreoffice-sdk-doc-4.4.6.3-2.2.mga5.x86_64.rpm
libreoffice-ure-4.4.6.3-2.2.mga5.x86_64.rpm
libreoffice-wiki-publisher-4.4.6.3-2.2.mga5.x86_64.rpm
libreoffice-writer-4.4.6.3-2.2.mga5.x86_64.rpm
libreoffice-xsltfilter-4.4.6.3-2.2.mga5.x86_64.rpm

Reproducible: 

Steps to Reproduce:
Comment 1 David Walser 2015-11-06 14:35:34 CET
Thanks for this.

I was thinking that some of the libraries that LO uses for file formats have newer bugfix releases that we should update too (you'd have these bugfixes if you used an upstream binary, for instance).

I think the libraries that *possibly* fit into this category are:
libe-book
libetonyek
libfreehand
liblangtag
libmwaw
libodfgen
liborcus
libvisio
libwps

What do you think?
Comment 2 David Walser 2015-11-06 15:09:26 CET
This update also fixes four security issues:
https://www.libreoffice.org/about-us/security/advisories/cve-2015-4551/
https://www.libreoffice.org/about-us/security/advisories/cve-2015-5212/
https://www.libreoffice.org/about-us/security/advisories/cve-2015-5213/
https://www.libreoffice.org/about-us/security/advisories/cve-2015-5214/

Debian and Ubuntu have issued advisories for this on November 5:
https://www.debian.org/security/2015/dsa-3394
http://www.ubuntu.com/usn/usn-2793-1/

Advisory:
========================

Updated libreoffice packages fix security vulnerabilities:

Federico Scrinzi discovered that LibreOffice incorrectly handled documents
inserted into Writer or Calc via links. If a user were tricked into opening
a specially crafted document, a remote attacker could possibly obtain the
contents of arbitrary files (CVE-2015-4551).

It was discovered that LibreOffice incorrectly handled PrinterSetup data
stored in ODF files. If a user were tricked into opening a specially
crafted ODF document, a remote attacker could cause LibreOffice to crash,
and possibly execute arbitrary code.(CVE-2015-5212).

It was discovered that LibreOffice incorrectly handled the number of pieces
in DOC files. If a user were tricked into opening a specially crafted DOC
document, a remote attacker could cause LibreOffice to crash, and possibly
execute arbitrary code (CVE-2015-5213).

It was discovered that LibreOffice incorrectly handled bookmarks in DOC
files. If a user were tricked into opening a specially crafted DOC
document, a remote attacker could cause LibreOffice to crash, and possibly
execute arbitrary code (CVE-2015-5214).

LibreOffice has been updated to version 4.4.6, which fixes these issues as
well as several other bugs.

References:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-4551
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-5212
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-5213
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-5214
https://www.libreoffice.org/about-us/security/advisories/cve-2015-4551/
https://www.libreoffice.org/about-us/security/advisories/cve-2015-5212/
https://www.libreoffice.org/about-us/security/advisories/cve-2015-5213/
https://www.libreoffice.org/about-us/security/advisories/cve-2015-5214/
http://download.documentfoundation.org/libreoffice/src/bugs-changelog-libreoffice-4-4-4-release-4.4.4.1.log
http://download.documentfoundation.org/libreoffice/src/bugs-changelog-libreoffice-4-4-4-release-4.4.4.2.log
http://download.documentfoundation.org/libreoffice/src/bugs-changelog-libreoffice-4-4-4-release-4.4.4.3.log
http://download.documentfoundation.org/libreoffice/src/bugs-changelog-libreoffice-4-4-5-release-4.4.5.1.log
http://download.documentfoundation.org/libreoffice/src/bugs-changelog-libreoffice-4-4-5-release-4.4.5.2.log
http://download.documentfoundation.org/libreoffice/src/bugs-changelog-libreoffice-4-4-6-release-4.4.6.1.log
http://download.documentfoundation.org/libreoffice/src/bugs-changelog-libreoffice-4-4-6-release-4.4.6.2.log
http://download.documentfoundation.org/libreoffice/src/bugs-changelog-libreoffice-4-4-6-release-4.4.6.3.log
http://www.ubuntu.com/usn/usn-2793-1/

Component: RPM Packages => Security

David Walser 2015-11-06 18:27:06 CET

URL: (none) => http://lwn.net/Vulnerabilities/663512/

David Walser 2015-11-06 18:28:09 CET

Severity: normal => major

Comment 3 Thierry Vignaud 2015-11-07 12:22:44 CET
Given the spotted security issues, I think we should forward it first & fast.
Then we can check for updates for the following libs:
- hyphen
- libabw
- libcdr
- libcmis
- libe-book
- libeot
- libetonyek
- libfreehand
- libgltf
- libixion
- liblangtag
- libmspub
- libmwaw
- libodfgen
- liborcus
- libpagemaker
- librevenge
- libvisio
- libwpd
- libwpg
- libwps
- mdds
- opencollada
- ucpp
Comment 4 Thierry Vignaud 2015-11-07 12:24:20 CET
For the record, FC updated to 4.4.6 too and added one more fix:
http://pkgs.fedoraproject.org/cgit/libreoffice.git/log/?h=f22
http://pkgs.fedoraproject.org/cgit/libreoffice.git/commit/?h=f22&id=3cb3af6f2d477e546a8e1b8b54d614f17fd0c94d
"Resolves: tdf#95210 SetHandleControllerPosition is busted"

But I won't push a new package just for that.
Comment 5 James Kerr 2015-11-07 15:09:04 CET
Updated to testing packages (en_GB locale) on mga5-64

No regressions observed. 

However, I only use writer and calc. 

With that caveat this update is OK for me on mga5-64
Comment 6 claire robinson 2015-11-07 17:54:14 CET
Adding OK from James' tests.

Whiteboard: (none) => mga5-64-ok

Comment 7 William Kenney 2015-11-09 15:55:39 CET
In VirtualBox, M5, KDE, 32-bit

Package(s) under test:
libreoffice-kde libreoffice-calc libreoffice-core libreoffice-writer
libreoffice-impress libreoffice-draw libreoffice-math

default install of libreoffice packages

[root@localhost wilcal]# urpmi libreoffice-kde
Package libreoffice-kde-4.4.2.2-4.mga5.i586 is already installed
[root@localhost wilcal]# urpmi libreoffice-calc
Package libreoffice-calc-4.4.2.2-4.mga5.i586 is already installed
[root@localhost wilcal]# urpmi libreoffice-core
Package libreoffice-core-4.4.2.2-4.mga5.i586 is already installed
[root@localhost wilcal]# urpmi libreoffice-writer
Package libreoffice-writer-4.4.2.2-4.mga5.i586 is already installed
[root@localhost wilcal]# urpmi libreoffice-impress
Package libreoffice-impress-4.4.2.2-4.mga5.i586 is already installed
[root@localhost wilcal]# urpmi libreoffice-draw
Package libreoffice-draw-4.4.2.2-4.mga5.i586 is already installed
[root@localhost wilcal]# urpmi libreoffice-math
Package libreoffice-math-4.4.2.2-4.mga5.i586 is already installed

All libreoffice packages work just fine.

install libreoffice packages from updates_testing

[root@localhost wilcal]# urpmi libreoffice-kde
Package libreoffice-kde-4.4.6.3-2.2.mga5.i586 is already installed
[root@localhost wilcal]# urpmi libreoffice-calc
Package libreoffice-calc-4.4.6.3-2.2.mga5.i586 is already installed
[root@localhost wilcal]# urpmi libreoffice-core
Package libreoffice-core-4.4.6.3-2.2.mga5.i586 is already installed
[root@localhost wilcal]# urpmi libreoffice-writer
Package libreoffice-writer-4.4.6.3-2.2.mga5.i586 is already installed
[root@localhost wilcal]# urpmi libreoffice-impress
Package libreoffice-impress-4.4.6.3-2.2.mga5.i586 is already installed
[root@localhost wilcal]# urpmi libreoffice-draw
Package libreoffice-draw-4.4.6.3-2.2.mga5.i586 is already installed
[root@localhost wilcal]# urpmi libreoffice-math
Package libreoffice-math-4.4.6.3-2.2.mga5.i586 is already installed

After update all libreoffice packages work just fine.

This update looks fine.

CC: (none) => wilcal.int

William Kenney 2015-11-09 15:55:58 CET

Whiteboard: mga5-64-ok => mga5-32-ok mga5-64-ok

Comment 8 Lewis Smith 2015-11-09 21:52:45 CET
Tested M5 x64

To add confirmation to earlier comments, I confirm that for at least Writer & Draw this LibreOffice seems OK.

CC: (none) => lewyssmith

Comment 9 claire robinson 2015-11-10 09:41:24 CET
Here also.

Validating.
claire robinson 2015-11-10 09:41:35 CET

Keywords: (none) => validated_update
CC: (none) => sysadmin-bugs

Dave Hodgins 2015-11-10 20:57:20 CET

CC: (none) => davidwhodgins
Whiteboard: mga5-32-ok mga5-64-ok => mga5-32-ok mga5-64-ok advisory

Comment 10 Mageia Robot 2015-11-10 22:27:34 CET
An update for this issue has been pushed to Mageia Updates repository.

http://advisories.mageia.org/MGASA-2015-0441.html

Status: NEW => RESOLVED
Resolution: (none) => FIXED


Note You need to log in before you can comment on or make changes to this bug.