Debian has issued an advisory on May 15: https://lwn.net/Articles/973885/ Mageia 9 is also affected.
Whiteboard: (none) => MGA9TOOStatus comment: (none) => Fixed upstream in 24.2.3 and 7.6.7Source RPM: (none) => libreoffice-24.2.2.2-1.mga10.src.rpmCVE: (none) => CVE-2024-3044
7.6... for M9 24.2.. for Cauldron Assigning to tv who routinely updates LibreOffice.
Assignee: bugsquad => thierry.vignaud
Suggested advisory: ======================== The updated packages fix a security vulnerability: Unchecked script execution in Graphic on-click binding in affected LibreOffice versions allows an attacker to create a document which without prompt will execute scripts built-into LibreOffice on clicking a graphic. Such scripts were previously deemed trusted but are now deemed untrusted. (CVE-2024-3044) References: https://lwn.net/Articles/973885/ ======================== Updated packages in core/updates_testing: ======================== autocorr-af-7.6.7.2-1.mga9 autocorr-bg-7.6.7.2-1.mga9 autocorr-ca-7.6.7.2-1.mga9 autocorr-cs-7.6.7.2-1.mga9 autocorr-da-7.6.7.2-1.mga9 autocorr-de-7.6.7.2-1.mga9 autocorr-dsb-7.6.7.2-1.mga9 autocorr-el-7.6.7.2-1.mga9 autocorr-en-7.6.7.2-1.mga9 autocorr-es-7.6.7.2-1.mga9 autocorr-fa-7.6.7.2-1.mga9 autocorr-fi-7.6.7.2-1.mga9 autocorr-fr-7.6.7.2-1.mga9 autocorr-ga-7.6.7.2-1.mga9 autocorr-hr-7.6.7.2-1.mga9 autocorr-hsb-7.6.7.2-1.mga9 autocorr-hu-7.6.7.2-1.mga9 autocorr-is-7.6.7.2-1.mga9 autocorr-it-7.6.7.2-1.mga9 autocorr-ja-7.6.7.2-1.mga9 autocorr-ko-7.6.7.2-1.mga9 autocorr-lb-7.6.7.2-1.mga9 autocorr-lt-7.6.7.2-1.mga9 autocorr-mn-7.6.7.2-1.mga9 autocorr-nl-7.6.7.2-1.mga9 autocorr-pl-7.6.7.2-1.mga9 autocorr-pt-7.6.7.2-1.mga9 autocorr-ro-7.6.7.2-1.mga9 autocorr-ru-7.6.7.2-1.mga9 autocorr-sk-7.6.7.2-1.mga9 autocorr-sl-7.6.7.2-1.mga9 autocorr-sr-7.6.7.2-1.mga9 autocorr-sv-7.6.7.2-1.mga9 autocorr-tr-7.6.7.2-1.mga9 autocorr-vi-7.6.7.2-1.mga9 autocorr-vro-7.6.7.2-1.mga9 autocorr-zh-7.6.7.2-1.mga9 libreoffice-7.6.7.2-1.mga9 libreoffice-base-7.6.7.2-1.mga9 libreoffice-calc-7.6.7.2-1.mga9 libreoffice-core-7.6.7.2-1.mga9 libreoffice-data-7.6.7.2-1.mga9 libreoffice-draw-7.6.7.2-1.mga9 libreoffice-emailmerge-7.6.7.2-1.mga9 libreoffice-filters-7.6.7.2-1.mga9 libreoffice-gdb-debug-support-7.6.7.2-1.mga9 libreoffice-glade-7.6.7.2-1.mga9 libreoffice-graphicfilter-7.6.7.2-1.mga9 libreoffice-gtk3-7.6.7.2-1.mga9 libreoffice-gtk4-7.6.7.2-1.mga9 libreoffice-help-ar-7.6.7.2-1.mga9 libreoffice-help-bg-7.6.7.2-1.mga9 libreoffice-help-bn-7.6.7.2-1.mga9 libreoffice-help-ca-7.6.7.2-1.mga9 libreoffice-help-cs-7.6.7.2-1.mga9 libreoffice-help-da-7.6.7.2-1.mga9 libreoffice-help-de-7.6.7.2-1.mga9 libreoffice-help-dz-7.6.7.2-1.mga9 libreoffice-help-el-7.6.7.2-1.mga9 libreoffice-help-en-7.6.7.2-1.mga9 libreoffice-help-eo-7.6.7.2-1.mga9 libreoffice-help-es-7.6.7.2-1.mga9 libreoffice-help-et-7.6.7.2-1.mga9 libreoffice-help-eu-7.6.7.2-1.mga9 libreoffice-help-fi-7.6.7.2-1.mga9 libreoffice-help-fr-7.6.7.2-1.mga9 libreoffice-help-gl-7.6.7.2-1.mga9 libreoffice-help-gu-7.6.7.2-1.mga9 libreoffice-help-he-7.6.7.2-1.mga9 libreoffice-help-hi-7.6.7.2-1.mga9 libreoffice-help-hr-7.6.7.2-1.mga9 libreoffice-help-hu-7.6.7.2-1.mga9 libreoffice-help-id-7.6.7.2-1.mga9 libreoffice-help-it-7.6.7.2-1.mga9 libreoffice-help-ja-7.6.7.2-1.mga9 libreoffice-help-ko-7.6.7.2-1.mga9 libreoffice-help-lt-7.6.7.2-1.mga9 libreoffice-help-lv-7.6.7.2-1.mga9 libreoffice-help-nb-7.6.7.2-1.mga9 libreoffice-help-nl-7.6.7.2-1.mga9 libreoffice-help-nn-7.6.7.2-1.mga9 libreoffice-help-pl-7.6.7.2-1.mga9 libreoffice-help-pt-7.6.7.2-1.mga9 libreoffice-help-pt_BR-7.6.7.2-1.mga9 libreoffice-help-ro-7.6.7.2-1.mga9 libreoffice-help-ru-7.6.7.2-1.mga9 libreoffice-help-si-7.6.7.2-1.mga9 libreoffice-help-sk-7.6.7.2-1.mga9 libreoffice-help-sl-7.6.7.2-1.mga9 libreoffice-help-sv-7.6.7.2-1.mga9 libreoffice-help-ta-7.6.7.2-1.mga9 libreoffice-help-tr-7.6.7.2-1.mga9 libreoffice-help-uk-7.6.7.2-1.mga9 libreoffice-help-zh_CN-7.6.7.2-1.mga9 libreoffice-help-zh_TW-7.6.7.2-1.mga9 libreoffice-impress-7.6.7.2-1.mga9 libreoffice-kf5-7.6.7.2-1.mga9 libreoffice-langpack-af-7.6.7.2-1.mga9 libreoffice-langpack-ar-7.6.7.2-1.mga9 libreoffice-langpack-as-7.6.7.2-1.mga9 libreoffice-langpack-bg-7.6.7.2-1.mga9 libreoffice-langpack-bn-7.6.7.2-1.mga9 libreoffice-langpack-br-7.6.7.2-1.mga9 libreoffice-langpack-ca-7.6.7.2-1.mga9 libreoffice-langpack-cs-7.6.7.2-1.mga9 libreoffice-langpack-cy-7.6.7.2-1.mga9 libreoffice-langpack-da-7.6.7.2-1.mga9 libreoffice-langpack-de-7.6.7.2-1.mga9 libreoffice-langpack-dz-7.6.7.2-1.mga9 libreoffice-langpack-el-7.6.7.2-1.mga9 libreoffice-langpack-en-7.6.7.2-1.mga9 libreoffice-langpack-eo-7.6.7.2-1.mga9 libreoffice-langpack-es-7.6.7.2-1.mga9 libreoffice-langpack-et-7.6.7.2-1.mga9 libreoffice-langpack-eu-7.6.7.2-1.mga9 libreoffice-langpack-fa-7.6.7.2-1.mga9 libreoffice-langpack-fi-7.6.7.2-1.mga9 libreoffice-langpack-fr-7.6.7.2-1.mga9 libreoffice-langpack-fy-7.6.7.2-1.mga9 libreoffice-langpack-ga-7.6.7.2-1.mga9 libreoffice-langpack-gl-7.6.7.2-1.mga9 libreoffice-langpack-gu-7.6.7.2-1.mga9 libreoffice-langpack-he-7.6.7.2-1.mga9 libreoffice-langpack-hi-7.6.7.2-1.mga9 libreoffice-langpack-hr-7.6.7.2-1.mga9 libreoffice-langpack-hu-7.6.7.2-1.mga9 libreoffice-langpack-id-7.6.7.2-1.mga9 libreoffice-langpack-it-7.6.7.2-1.mga9 libreoffice-langpack-ja-7.6.7.2-1.mga9 libreoffice-langpack-kk-7.6.7.2-1.mga9 libreoffice-langpack-kn-7.6.7.2-1.mga9 libreoffice-langpack-ko-7.6.7.2-1.mga9 libreoffice-langpack-lt-7.6.7.2-1.mga9 libreoffice-langpack-lv-7.6.7.2-1.mga9 libreoffice-langpack-mai-7.6.7.2-1.mga9 libreoffice-langpack-ml-7.6.7.2-1.mga9 libreoffice-langpack-mr-7.6.7.2-1.mga9 libreoffice-langpack-nb-7.6.7.2-1.mga9 libreoffice-langpack-nl-7.6.7.2-1.mga9 libreoffice-langpack-nn-7.6.7.2-1.mga9 libreoffice-langpack-nr-7.6.7.2-1.mga9 libreoffice-langpack-nso-7.6.7.2-1.mga9 libreoffice-langpack-or-7.6.7.2-1.mga9 libreoffice-langpack-pa-7.6.7.2-1.mga9 libreoffice-langpack-pl-7.6.7.2-1.mga9 libreoffice-langpack-pt-7.6.7.2-1.mga9 libreoffice-langpack-pt_BR-7.6.7.2-1.mga9 libreoffice-langpack-ro-7.6.7.2-1.mga9 libreoffice-langpack-ru-7.6.7.2-1.mga9 libreoffice-langpack-si-7.6.7.2-1.mga9 libreoffice-langpack-sk-7.6.7.2-1.mga9 libreoffice-langpack-sl-7.6.7.2-1.mga9 libreoffice-langpack-sr-7.6.7.2-1.mga9 libreoffice-langpack-ss-7.6.7.2-1.mga9 libreoffice-langpack-st-7.6.7.2-1.mga9 libreoffice-langpack-sv-7.6.7.2-1.mga9 libreoffice-langpack-ta-7.6.7.2-1.mga9 libreoffice-langpack-te-7.6.7.2-1.mga9 libreoffice-langpack-th-7.6.7.2-1.mga9 libreoffice-langpack-tn-7.6.7.2-1.mga9 libreoffice-langpack-tr-7.6.7.2-1.mga9 libreoffice-langpack-ts-7.6.7.2-1.mga9 libreoffice-langpack-uk-7.6.7.2-1.mga9 libreoffice-langpack-ve-7.6.7.2-1.mga9 libreoffice-langpack-xh-7.6.7.2-1.mga9 libreoffice-langpack-zh_CN-7.6.7.2-1.mga9 libreoffice-langpack-zh_TW-7.6.7.2-1.mga9 libreoffice-langpack-zu-7.6.7.2-1.mga9 libreoffice-librelogo-7.6.7.2-1.mga9 libreoffice-math-7.6.7.2-1.mga9 libreoffice-nlpsolver-7.6.7.2-1.mga9 libreoffice-officebean-7.6.7.2-1.mga9 libreoffice-officebean-common-7.6.7.2-1.mga9 libreoffice-ogltrans-7.6.7.2-1.mga9 libreoffice-opensymbol-fonts-7.6.7.2-1.mga9 libreoffice-pdfimport-7.6.7.2-1.mga9 libreoffice-postgresql-7.6.7.2-1.mga9 libreoffice-pyuno-7.6.7.2-1.mga9 libreoffice-sdk-7.6.7.2-1.mga9 libreoffice-sdk-doc-7.6.7.2-1.mga9 libreoffice-ure-7.6.7.2-1.mga9 libreoffice-ure-common-7.6.7.2-1.mga9 libreoffice-wiki-publisher-7.6.7.2-1.mga9 libreoffice-writer-7.6.7.2-1.mga9 libreoffice-x11-7.6.7.2-1.mga9 libreoffice-xsltfilter-7.6.7.2-1.mga9 libreofficekit-7.6.7.2-1.mga9 libreofficekit-devel-7.6.7.2-1.mga9 from SRPM: libreoffice-7.6.7.2-1.mga9.src.rpm
Status: NEW => ASSIGNEDStatus comment: Fixed upstream in 24.2.3 and 7.6.7 => (none)Assignee: thierry.vignaud => qa-bugsSource RPM: libreoffice-24.2.2.2-1.mga10.src.rpm => libreoffice-7.6.6.3-1.mga9.src.rpmVersion: Cauldron => 9Whiteboard: MGA9TOO => (none)
Keywords: (none) => advisory
RH mageia 9 x86_64 Updated without issues Writer open my documents without issues Calc open my spreadsheets without issues Draw start without issues Test Base report with https://bugs.mageia.org/attachment.cgi?id=12543 OK Impress start without issue Math start without issue
mga9-64 Plasma X11 One system with nvidia470, another with nouveau Swedish localisation OK incl help Opened a few files I had created previously, edited, saved, printed.
CC: (none) => fri
RH mageia 9 i586 Updated without issues Writer open my documents Calc open my spreadsheets Draw start without issues Impress start without issues Base start without issues Math start without issues
updated without issue created a new writer document exported as a pdf - ok calc seems ok impress seems ok draw seems ok
CC: (none) => westel
MGA9-64 Plasma Wayland on HP-Pavillion No installation issues. Tested with file types doc, docx, odt, xlxsx, ods with data connection to odb, ppltx, odp, odb . All works correctly except for the long outstanding bug with reports from odb.
CC: (none) => herman.viaene
M9 x86_64 xfce GTX 1080 Ti graphics. libreoffice 7.6.7.2-1.mga9 installed. libreoffice writer 'stress-tested' with my 660 Mb .odt file (of my stingless bees with a myriad pics inserted, which libreoffice writer had problems coping with in earlier iterations) and LO behaved just fine.
CC: (none) => tablackwell
MGA9-64, Plasma The following 21 packages are going to be installed: - autocorr-en-7.6.7.2-1.mga9.noarch - libreoffice-calc-7.6.7.2-1.mga9.x86_64 - libreoffice-core-7.6.7.2-1.mga9.x86_64 - libreoffice-data-7.6.7.2-1.mga9.x86_64 - libreoffice-draw-7.6.7.2-1.mga9.x86_64 - libreoffice-emailmerge-7.6.7.2-1.mga9.x86_64 - libreoffice-graphicfilter-7.6.7.2-1.mga9.x86_64 - libreoffice-gtk3-7.6.7.2-1.mga9.x86_64 - libreoffice-help-en-7.6.7.2-1.mga9.x86_64 - libreoffice-impress-7.6.7.2-1.mga9.x86_64 - libreoffice-kf5-7.6.7.2-1.mga9.x86_64 - libreoffice-langpack-en-7.6.7.2-1.mga9.x86_64 - libreoffice-math-7.6.7.2-1.mga9.x86_64 - libreoffice-ogltrans-7.6.7.2-1.mga9.x86_64 - libreoffice-opensymbol-fonts-7.6.7.2-1.mga9.noarch - libreoffice-pdfimport-7.6.7.2-1.mga9.x86_64 - libreoffice-pyuno-7.6.7.2-1.mga9.x86_64 - libreoffice-ure-7.6.7.2-1.mga9.x86_64 - libreoffice-ure-common-7.6.7.2-1.mga9.x86_64 - libreoffice-writer-7.6.7.2-1.mga9.x86_64 - libreoffice-xsltfilter-7.6.7.2-1.mga9.x86_64 -- used calc without issue writer without issue - many documents impress opens and templates work English is working or me
CC: (none) => brtians1
Whiteboard: (none) => MGA9-32-OK,MGA9-64-OKCC: (none) => andrewsfarm
I spent some more time on another machine with a larger installation of Libreoffice. Working.
Thanks, guys. I had planned to do a test of my own last night, but I was just too tired. I am glad to have you all here. Validating.
Keywords: (none) => validated_updateCC: (none) => sysadmin-bugs
An update for this issue has been pushed to the Mageia Updates repository. https://advisories.mageia.org/MGASA-2024-0209.html
Resolution: (none) => FIXEDStatus: ASSIGNED => RESOLVED