This bug was fixed in the package libreoffice -
4:24.2.5-0ubuntu0.24.04.2

---------------
libreoffice (4:24.2.5-0ubuntu0.24.04.2) noble-security; urgency=medium

  * No-change rebuild in the -security pocket to fix CVE-2024-6472.
    (LP: #2076130)

 -- Marc Deslauriers <marc.deslauri...@ubuntu.com>  Tue, 13 Aug 2024
10:32:23 -0400

** Changed in: libreoffice (Ubuntu Noble)
       Status: New => Fix Released

** CVE added: https://cve.mitre.org/cgi-bin/cvename.cgi?name=2024-6472

** Changed in: libreoffice (Ubuntu Focal)
       Status: In Progress => Fix Released

-- 
You received this bug notification because you are a member of Desktop
Packages, which is subscribed to libreoffice in Ubuntu.
https://bugs.launchpad.net/bugs/2076130

Title:
  CVE-2024-6472

Status in libreoffice package in Ubuntu:
  Fix Released
Status in libreoffice source package in Focal:
  Fix Released
Status in libreoffice source package in Jammy:
  In Progress
Status in libreoffice source package in Noble:
  Fix Released
Status in libreoffice source package in Oracular:
  Fix Released

Bug description:
  CVE-2024-6472: "Ability to trust not validated macro signatures removed in 
high security mode"
  https://www.libreoffice.org/about-us/security/advisories/cve-2024-6472/

  https://git.libreoffice.org/core/+/da570d9adb324b143ab5a05683fc17a1c90feaec
  https://gerrit.libreoffice.org/c/core/+/169525

  https://ubuntu.com/security/CVE-2024-6472

  * Noble 24.04: Fix is included in 24.2.5 SRU
    - https://bugs.launchpad.net/ubuntu/+source/libreoffice/+bug/2073054
  * Jammy 22.04: Backport of patch to 7.3.7 required
    - https://gerrit.libreoffice.org/c/core/+/171313
    - 
https://git.launchpad.net/~libreoffice/ubuntu/+source/libreoffice/log/?h=wip/jammy-7.3
  * Focal 20.04: Backport of patch to 6.4.7 required
    - https://gerrit.libreoffice.org/c/core/+/171323
    - 
https://git.launchpad.net/~libreoffice/ubuntu/+source/libreoffice/log/?h=wip/focal-6.4

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/libreoffice/+bug/2076130/+subscriptions


-- 
Mailing list: https://launchpad.net/~desktop-packages
Post to     : desktop-packages@lists.launchpad.net
Unsubscribe : https://launchpad.net/~desktop-packages
More help   : https://help.launchpad.net/ListHelp

Reply via email to