CVE-2015-4551
libreoffice - security update
EPSS 13.8%
描述
LibreOffice before 4.4.5 and Apache OpenOffice before 4.1.2 uses the stored LinkUpdateMode configuration information in OpenDocument Format files and templates when handling links, which might allow remote attackers to obtain sensitive information via a crafted document, which embeds data from local files into (1) Calc or (2) Writer.
如何修補 CVE-2015-4551
要修補 CVE-2015-4551,請將受影響套件升級到下列已修補版本。
- Debian/libreoffice—升級至 1:5.0.1~rc1-1 或更新版本
- Debian/libreoffice—升級至 1:3.5.4+dfsg2-0+deb7u5 或更新版本
CVE-2015-4551 正在被利用嗎?
中等 — EPSS 為 13.8%,可持續追蹤但非最高優先。
受影響套件(2)
- from 0, < 1:5.0.1~rc1-1
- from 0, < 1:3.5.4+dfsg2-0+deb7u5