Bug 1026640 - (CVE-2017-3157) VUL-0: CVE-2017-3157: libreoffice: Arbitrary file disclosure in Calc and Writer
VUL-0: CVE-2017-3157: libreoffice: Arbitrary file disclosure in Calc and Writer
Classification: Novell Products
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents
Other Other
: P5 - None : Normal
: ---
Assigned To: Tomáš Chvátal
Security Team bot
Depends on:
  Show dependency treegraph
Reported: 2017-02-23 12:06 UTC by Marcus Meissner
Modified: 2017-02-23 13:01 UTC (History)
1 user (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Note You need to log in before you can comment on or make changes to this bug.
Description Marcus Meissner 2017-02-23 12:06:37 UTC


Title: CVE-2017-3157 Arbitrary file disclosure in Calc and Writer

Announced: February 22, 2017

Fixed in: LibreOffice 5.1.6/5.2.2/5.3.0


Embedded Objects in writer and calc can contain previews of their content. A document can be crafted which contains an embedded object that is a link to an existing file on the targets system. On load the preview of the embedded object will be updated to reflect the content of the file on the target system. In the case of LibreOffice used as an online service that preview of data on the target system could be used to expose details of the environment LibreOffice is running in. In the case of LibreOffice as a standard desktop application, the preview could be concealed in hidden sections and retrieved by the attacker if the document is saved and returned to sender.

In later version of LibreOffice without this flaw the LinkUpdateMode feature has been expanded to additionally control the update of previews of embedded objects as well as its prior function to control the update of embedded object contents.

All users are recommended to upgrade to LibreOffice >= 5.1.6 or >= 5.2.5 or >= 5.3.0

Thanks to Ben Hayak for discovering this flaw.


Comment 1 Tomáš Chvátal 2017-02-23 12:13:30 UTC
No affected codestream?
Comment 2 Marcus Meissner 2017-02-23 12:31:21 UTC
we seem to have 5.2.3 in SLE 12 SP1+SP2 and openSUSE Leap 42.*

So I think we are good.
Comment 3 Bernhard Wiedemann 2017-02-23 13:01:48 UTC
This is an autogenerated message for OBS integration:
This bug (1026640) was mentioned in
https://build.opensuse.org/request/show/460020 Factory / libreoffice