SUSE update for libreoffice



Published: 2022-04-04
Risk Low
Patch available YES
Number of vulnerabilities 1
CVE-ID CVE-2021-25636
CWE-ID CWE-295
Exploitation vector Network
Public exploit N/A
Vulnerable software
Subscribe
SUSE Linux Enterprise Workstation Extension
Operating systems & Components / Operating system

SUSE Linux Enterprise Desktop
Operating systems & Components / Operating system

SUSE Linux Enterprise Software Development Kit
Operating systems & Components / Operating system

SUSE Linux Enterprise Server for SAP Applications
Operating systems & Components / Operating system

SUSE Linux Enterprise Server
Operating systems & Components / Operating system

libreoffice-sdk-debuginfo
Operating systems & Components / Operating system package or component

libreoffice-sdk
Operating systems & Components / Operating system package or component

libreoffice-l10n-zu
Operating systems & Components / Operating system package or component

libreoffice-l10n-zh_TW
Operating systems & Components / Operating system package or component

libreoffice-l10n-zh_CN
Operating systems & Components / Operating system package or component

libreoffice-l10n-xh
Operating systems & Components / Operating system package or component

libreoffice-l10n-uk
Operating systems & Components / Operating system package or component

libreoffice-l10n-sv
Operating systems & Components / Operating system package or component

libreoffice-l10n-sk
Operating systems & Components / Operating system package or component

libreoffice-l10n-ru
Operating systems & Components / Operating system package or component

libreoffice-l10n-ro
Operating systems & Components / Operating system package or component

libreoffice-l10n-pt_PT
Operating systems & Components / Operating system package or component

libreoffice-l10n-pt_BR
Operating systems & Components / Operating system package or component

libreoffice-l10n-pl
Operating systems & Components / Operating system package or component

libreoffice-l10n-nn
Operating systems & Components / Operating system package or component

libreoffice-l10n-nl
Operating systems & Components / Operating system package or component

libreoffice-l10n-nb
Operating systems & Components / Operating system package or component

libreoffice-l10n-lt
Operating systems & Components / Operating system package or component

libreoffice-l10n-ko
Operating systems & Components / Operating system package or component

libreoffice-l10n-ja
Operating systems & Components / Operating system package or component

libreoffice-l10n-it
Operating systems & Components / Operating system package or component

libreoffice-l10n-hu
Operating systems & Components / Operating system package or component

libreoffice-l10n-hr
Operating systems & Components / Operating system package or component

libreoffice-l10n-hi
Operating systems & Components / Operating system package or component

libreoffice-l10n-gu
Operating systems & Components / Operating system package or component

libreoffice-l10n-fr
Operating systems & Components / Operating system package or component

libreoffice-l10n-fi
Operating systems & Components / Operating system package or component

libreoffice-l10n-es
Operating systems & Components / Operating system package or component

libreoffice-l10n-en
Operating systems & Components / Operating system package or component

libreoffice-l10n-de
Operating systems & Components / Operating system package or component

libreoffice-l10n-da
Operating systems & Components / Operating system package or component

libreoffice-l10n-cs
Operating systems & Components / Operating system package or component

libreoffice-l10n-ca
Operating systems & Components / Operating system package or component

libreoffice-l10n-bg
Operating systems & Components / Operating system package or component

libreoffice-l10n-ar
Operating systems & Components / Operating system package or component

libreoffice-l10n-af
Operating systems & Components / Operating system package or component

libreoffice-icon-themes
Operating systems & Components / Operating system package or component

libreoffice-branding-upstream
Operating systems & Components / Operating system package or component

libreoffice-writer-extensions
Operating systems & Components / Operating system package or component

libreoffice-writer-debuginfo
Operating systems & Components / Operating system package or component

libreoffice-writer
Operating systems & Components / Operating system package or component

libreoffice-pyuno-debuginfo
Operating systems & Components / Operating system package or component

libreoffice-pyuno
Operating systems & Components / Operating system package or component

libreoffice-officebean-debuginfo
Operating systems & Components / Operating system package or component

libreoffice-officebean
Operating systems & Components / Operating system package or component

libreoffice-math-debuginfo
Operating systems & Components / Operating system package or component

libreoffice-math
Operating systems & Components / Operating system package or component

libreoffice-mailmerge
Operating systems & Components / Operating system package or component

libreoffice-librelogo
Operating systems & Components / Operating system package or component

libreoffice-impress-debuginfo
Operating systems & Components / Operating system package or component

libreoffice-impress
Operating systems & Components / Operating system package or component

libreoffice-gtk3-debuginfo
Operating systems & Components / Operating system package or component

libreoffice-gtk3
Operating systems & Components / Operating system package or component

libreoffice-gnome-debuginfo
Operating systems & Components / Operating system package or component

libreoffice-gnome
Operating systems & Components / Operating system package or component

libreoffice-filters-optional
Operating systems & Components / Operating system package or component

libreoffice-draw-debuginfo
Operating systems & Components / Operating system package or component

libreoffice-draw
Operating systems & Components / Operating system package or component

libreoffice-debugsource
Operating systems & Components / Operating system package or component

libreoffice-debuginfo
Operating systems & Components / Operating system package or component

libreoffice-calc-extensions
Operating systems & Components / Operating system package or component

libreoffice-calc-debuginfo
Operating systems & Components / Operating system package or component

libreoffice-calc
Operating systems & Components / Operating system package or component

libreoffice-base-drivers-postgresql-debuginfo
Operating systems & Components / Operating system package or component

libreoffice-base-drivers-postgresql
Operating systems & Components / Operating system package or component

libreoffice-base-debuginfo
Operating systems & Components / Operating system package or component

libreoffice-base
Operating systems & Components / Operating system package or component

libreoffice
Operating systems & Components / Operating system package or component

Vendor SUSE

Security Bulletin

This security bulletin contains one low risk vulnerability.

1) Improper certificate validation

EUVDB-ID: #VU60762

Risk: Low

CVSSv3.1: 3.8 [CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N/E:U/RL:O/RC:C]

CVE-ID: CVE-2021-25636

CWE-ID: CWE-295 - Improper Certificate Validation

Exploit availability: No

Description

The vulnerability allows a remote attacker to perform a spoofing attack.

The vulnerability exists due to improper certificate validation when processing digital signatures of ODF documents. A remote attacker can modify the documentsignatures.xml or macrosignatures.xml stream within the document to contain both "X509Data" and "KeyValue" children of the "KeyInfo" tag[1], which when opened caused LibreOffice to verify using the "KeyValue" but to report verification with the unrelated "X509Data" value.

Mitigation

Update the affected package libreoffice to the latest version.

Vulnerable software versions

SUSE Linux Enterprise Workstation Extension: 12-SP5

SUSE Linux Enterprise Desktop: 12-SP5

SUSE Linux Enterprise Software Development Kit: 12-SP5

SUSE Linux Enterprise Server for SAP Applications: 12-SP5

SUSE Linux Enterprise Server: 12-SP5

libreoffice-sdk-debuginfo: before 7.2.5.1-48.19.4

libreoffice-sdk: before 7.2.5.1-48.19.4

libreoffice-l10n-zu: before 7.2.5.1-48.19.4

libreoffice-l10n-zh_TW: before 7.2.5.1-48.19.4

libreoffice-l10n-zh_CN: before 7.2.5.1-48.19.4

libreoffice-l10n-xh: before 7.2.5.1-48.19.4

libreoffice-l10n-uk: before 7.2.5.1-48.19.4

libreoffice-l10n-sv: before 7.2.5.1-48.19.4

libreoffice-l10n-sk: before 7.2.5.1-48.19.4

libreoffice-l10n-ru: before 7.2.5.1-48.19.4

libreoffice-l10n-ro: before 7.2.5.1-48.19.4

libreoffice-l10n-pt_PT: before 7.2.5.1-48.19.4

libreoffice-l10n-pt_BR: before 7.2.5.1-48.19.4

libreoffice-l10n-pl: before 7.2.5.1-48.19.4

libreoffice-l10n-nn: before 7.2.5.1-48.19.4

libreoffice-l10n-nl: before 7.2.5.1-48.19.4

libreoffice-l10n-nb: before 7.2.5.1-48.19.4

libreoffice-l10n-lt: before 7.2.5.1-48.19.4

libreoffice-l10n-ko: before 7.2.5.1-48.19.4

libreoffice-l10n-ja: before 7.2.5.1-48.19.4

libreoffice-l10n-it: before 7.2.5.1-48.19.4

libreoffice-l10n-hu: before 7.2.5.1-48.19.4

libreoffice-l10n-hr: before 7.2.5.1-48.19.4

libreoffice-l10n-hi: before 7.2.5.1-48.19.4

libreoffice-l10n-gu: before 7.2.5.1-48.19.4

libreoffice-l10n-fr: before 7.2.5.1-48.19.4

libreoffice-l10n-fi: before 7.2.5.1-48.19.4

libreoffice-l10n-es: before 7.2.5.1-48.19.4

libreoffice-l10n-en: before 7.2.5.1-48.19.4

libreoffice-l10n-de: before 7.2.5.1-48.19.4

libreoffice-l10n-da: before 7.2.5.1-48.19.4

libreoffice-l10n-cs: before 7.2.5.1-48.19.4

libreoffice-l10n-ca: before 7.2.5.1-48.19.4

libreoffice-l10n-bg: before 7.2.5.1-48.19.4

libreoffice-l10n-ar: before 7.2.5.1-48.19.4

libreoffice-l10n-af: before 7.2.5.1-48.19.4

libreoffice-icon-themes: before 7.2.5.1-48.19.4

libreoffice-branding-upstream: before 7.2.5.1-48.19.4

libreoffice-writer-extensions: before 7.2.5.1-48.19.4

libreoffice-writer-debuginfo: before 7.2.5.1-48.19.4

libreoffice-writer: before 7.2.5.1-48.19.4

libreoffice-pyuno-debuginfo: before 7.2.5.1-48.19.4

libreoffice-pyuno: before 7.2.5.1-48.19.4

libreoffice-officebean-debuginfo: before 7.2.5.1-48.19.4

libreoffice-officebean: before 7.2.5.1-48.19.4

libreoffice-math-debuginfo: before 7.2.5.1-48.19.4

libreoffice-math: before 7.2.5.1-48.19.4

libreoffice-mailmerge: before 7.2.5.1-48.19.4

libreoffice-librelogo: before 7.2.5.1-48.19.4

libreoffice-impress-debuginfo: before 7.2.5.1-48.19.4

libreoffice-impress: before 7.2.5.1-48.19.4

libreoffice-gtk3-debuginfo: before 7.2.5.1-48.19.4

libreoffice-gtk3: before 7.2.5.1-48.19.4

libreoffice-gnome-debuginfo: before 7.2.5.1-48.19.4

libreoffice-gnome: before 7.2.5.1-48.19.4

libreoffice-filters-optional: before 7.2.5.1-48.19.4

libreoffice-draw-debuginfo: before 7.2.5.1-48.19.4

libreoffice-draw: before 7.2.5.1-48.19.4

libreoffice-debugsource: before 7.2.5.1-48.19.4

libreoffice-debuginfo: before 7.2.5.1-48.19.4

libreoffice-calc-extensions: before 7.2.5.1-48.19.4

libreoffice-calc-debuginfo: before 7.2.5.1-48.19.4

libreoffice-calc: before 7.2.5.1-48.19.4

libreoffice-base-drivers-postgresql-debuginfo: before 7.2.5.1-48.19.4

libreoffice-base-drivers-postgresql: before 7.2.5.1-48.19.4

libreoffice-base-debuginfo: before 7.2.5.1-48.19.4

libreoffice-base: before 7.2.5.1-48.19.4

libreoffice: before 7.2.5.1-48.19.4

CPE2.3 External links

http://www.suse.com/support/update/announcement/2022/suse-su-20221093-1/


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.



###SIDEBAR###