*** This bug is a security vulnerability ***

Public security bug reported:

CVE-2024-6472: "Ability to trust not validated macro signatures removed in high 
security mode"
https://www.libreoffice.org/about-us/security/advisories/cve-2024-6472/

https://git.libreoffice.org/core/+/da570d9adb324b143ab5a05683fc17a1c90feaec
https://gerrit.libreoffice.org/c/core/+/169525

https://ubuntu.com/security/CVE-2024-6472

* Noble 24.04: Fix is included in 24.2.5 SRU
  - https://bugs.launchpad.net/ubuntu/+source/libreoffice/+bug/2073054
* Jammy 22.04: Backport of patch to 7.3.7 required
  - https://gerrit.libreoffice.org/c/core/+/171313
* Focal 20.04: Backport of patch to 6.4.7 required
  - https://gerrit.libreoffice.org/c/core/+/171323

** Affects: libreoffice (Ubuntu)
     Importance: Undecided
         Status: Fix Released

** Affects: libreoffice (Ubuntu Focal)
     Importance: Undecided
         Status: New

** Affects: libreoffice (Ubuntu Jammy)
     Importance: Undecided
         Status: New

** Affects: libreoffice (Ubuntu Noble)
     Importance: Undecided
         Status: New

** Affects: libreoffice (Ubuntu Oracular)
     Importance: Undecided
         Status: Fix Released

** Also affects: libreoffice (Ubuntu Jammy)
   Importance: Undecided
       Status: New

** Also affects: libreoffice (Ubuntu Focal)
   Importance: Undecided
       Status: New

** Also affects: libreoffice (Ubuntu Noble)
   Importance: Undecided
       Status: New

** Also affects: libreoffice (Ubuntu Oracular)
   Importance: Undecided
       Status: New

** Changed in: libreoffice (Ubuntu Oracular)
       Status: New => Fix Released

** Information type changed from Public to Public Security

-- 
You received this bug notification because you are a member of Desktop
Packages, which is subscribed to libreoffice in Ubuntu.
https://bugs.launchpad.net/bugs/2076130

Title:
  CVE-2024-6472

Status in libreoffice package in Ubuntu:
  Fix Released
Status in libreoffice source package in Focal:
  New
Status in libreoffice source package in Jammy:
  New
Status in libreoffice source package in Noble:
  New
Status in libreoffice source package in Oracular:
  Fix Released

Bug description:
  CVE-2024-6472: "Ability to trust not validated macro signatures removed in 
high security mode"
  https://www.libreoffice.org/about-us/security/advisories/cve-2024-6472/

  https://git.libreoffice.org/core/+/da570d9adb324b143ab5a05683fc17a1c90feaec
  https://gerrit.libreoffice.org/c/core/+/169525

  https://ubuntu.com/security/CVE-2024-6472

  * Noble 24.04: Fix is included in 24.2.5 SRU
    - https://bugs.launchpad.net/ubuntu/+source/libreoffice/+bug/2073054
  * Jammy 22.04: Backport of patch to 7.3.7 required
    - https://gerrit.libreoffice.org/c/core/+/171313
  * Focal 20.04: Backport of patch to 6.4.7 required
    - https://gerrit.libreoffice.org/c/core/+/171323

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/libreoffice/+bug/2076130/+subscriptions


-- 
Mailing list: https://launchpad.net/~desktop-packages
Post to     : desktop-packages@lists.launchpad.net
Unsubscribe : https://launchpad.net/~desktop-packages
More help   : https://help.launchpad.net/ListHelp

Reply via email to