UbuntuUpdates.org

Package "libjuh-java"

Name: libjuh-java

Description:

LibreOffice UNO runtime environment -- Java Uno helper

Latest version: 1:6.4.7-0ubuntu0.20.04.12
Release: focal (20.04)
Level: security
Repository: main
Head package: libreoffice
Homepage: http://www.libreoffice.org

Links


Download "libjuh-java"


Other versions of "libjuh-java" in Focal

Repository Area Version
base main 1:6.4.2-0ubuntu3
updates main 1:6.4.7-0ubuntu0.20.04.12
backports main 1:7.4.7-0ubuntu0.22.10.1~bpo20.04.1
PPA: LibreOffice 4:7.6.7-0ubuntu0.20.04.1~lo1

Changelog

Version: 1:6.4.7-0ubuntu0.20.04.12 2024-09-19 16:06:59 UTC

  libreoffice (1:6.4.7-0ubuntu0.20.04.12) focal-security; urgency=medium

  * SECURITY UPDATE: Signatures in "repair mode" should not be trusted
    - debian/patches/CVE-2024-7788.patch: sfx2: SfxObjectShell should
      not trust any signature on repaired package
    - CVE-2024-7788

 -- Rico Tzschichholz <email address hidden> Wed, 18 Sep 2024 17:10:51 +0200

Source diff to previous version
CVE-2024-7788 Improper Digital Signature InvalidationĀ  vulnerability in Zip Repair Mode of The Document Foundation LibreOffice allows Signature forgery vulnerabili

Version: 1:6.4.7-0ubuntu0.20.04.11 2024-08-15 14:07:12 UTC

  libreoffice (1:6.4.7-0ubuntu0.20.04.11) focal-security; urgency=medium

  * SECURITY UPDATE: Ability to trust not validated macro signatures
    removed in high security mode (LP: #2076130)
    - debian/patches/CVE-2024-6472.patch: remove ability to trust not
      validated macro signatures in high security
    - CVE-2024-6472

 -- Rico Tzschichholz <email address hidden> Mon, 05 Aug 2024 21:28:04 +0200

Source diff to previous version
2076130 CVE-2024-6472
CVE-2024-6472 Certificate Validation user interface in LibreOffice allows potential vulnerability. Signed macros are scripts that have been digitally signed by

Version: 1:6.4.7-0ubuntu0.20.04.10 2024-05-28 13:07:06 UTC

  libreoffice (1:6.4.7-0ubuntu0.20.04.10) focal-security; urgency=medium

  * SECURITY UPDATE: Graphic on-click binding allows unchecked script
     execution
    - debian/patches/CVE-2024-3044.patch: add notify for script use
    - CVE-2024-3044

 -- Rico Tzschichholz <email address hidden> Wed, 15 May 2024 09:06:02 +0200

Source diff to previous version
CVE-2024-3044 Unchecked script execution in Graphic on-click binding in affected LibreOffice versions allows an attacker to create a document which without prompt

Version: 1:6.4.7-0ubuntu0.20.04.9 2023-12-14 15:06:51 UTC

  libreoffice (1:6.4.7-0ubuntu0.20.04.9) focal-security; urgency=medium

  * SECURITY UPDATE: Improper input validation enabling arbitrary Gstreamer
     pipeline injection
    - debian/patches/CVE-2023-6185.patch: escape url passed to gstreamer
    - CVE-2023-6185
  * SECURITY UPDATE: Link targets allow arbitrary script execution
    - debian/patches/CVE-2023-6186-*.patch: multiple commits to fix
      security issues.
    - CVE-2023-6186
  * patches/CppunitTest_desktop_lib-adjust-asserts-so-this-works.patch:
    - Usage of expired certificates in CppunitTest_desktop_lib:
      adjust asserts so this works again

 -- Rico Tzschichholz <email address hidden> Mon, 11 Dec 2023 15:41:29 +0100

Source diff to previous version
CVE-2023-6185 Improper input validation enabling arbitrary Gstreamer pipeline injection
CVE-2023-6186 Link targets allow arbitrary script execution

Version: 1:6.4.7-0ubuntu0.20.04.8 2023-06-07 07:14:15 UTC

  libreoffice (1:6.4.7-0ubuntu0.20.04.8) focal-security; urgency=high

  * SECURITY UPDATE: Remote documents loaded without prompt via IFrame
    - debian/patches/CVE-2023-2255-*.patch: multiple commits to fix
      security issues.
    - CVE-2023-2255
  * SECURITY UPDATE: Array Index UnderFlow in Calc Formula Parsing
    - debian/patches/CVE-2023-0950.patch: Obtain actual 0-parameter count
      for OR(), AND() and 1-parameter functions
    - CVE-2023-0950

 -- Rico Tzschichholz <email address hidden> Thu, 25 May 2023 22:52:23 +0200

CVE-2023-2255 Improper access control in editor components of The Document Foundation LibreOffice allowed an attacker to craft a document that would cause external
CVE-2023-0950 Improper Validation of Array Index vulnerability in the spreadsheet component of The Document Foundation LibreOffice allows an attacker to craft a sp



About   -   Send Feedback to @ubuntu_updates