Errata ID | 235 |
---|---|
Date | 2019-08-22 |
Source package | libreoffice |
Fixed in version | 1:5.2.7-1+deb9u10 |
Description | This update addresses the following issues: * Insufficient url validation allowing LibreLogo script execution (CVE-2019-9850) * LibreLogo global-event script execution (CVE-2019-9851) * Insufficient URL encoding flaw in allowed script location check (CVE-2019-9852) |
Additional notes | |
CVE ID | CVE-2019-9850 CVE-2019-9851 CVE-2019-9852 |
UCS Bug number | #50018 |