========================================================================== Ubuntu Security Notice USN-3472-1 November 02, 2017 libreoffice vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 14.04 LTS Summary: LibreOffice could be made to crash or run programs as your login if it opened a specially crafted file. Software Description: - libreoffice: Office productivity suite Details: Marcin Noga discovered that LibreOffice incorrectly handled PPT documents. If a user were tricked into opening a specially crafted PPT document, a remote attacker could cause LibreOffice to crash, and possibly execute arbitrary code. (CVE-2017-12607) Marcin Noga discovered that LibreOffice incorrectly handled Word documents. If a user were tricked into opening a specially crafted Word document, a remote attacker could cause LibreOffice to crash, and possibly execute arbitrary code. (CVE-2017-12608) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 14.04 LTS: libreoffice-core 1:4.2.8-0ubuntu5.2 After a standard system update you need to restart LibreOffice to make all the necessary changes. References: https://www.ubuntu.com/usn/usn-3472-1 CVE-2017-12607, CVE-2017-12608 Package Information: https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu5.2