Bugzilla – Bug 1217578
VUL-0: CVE-2023-6186: libreoffice: Link targets allow arbitrary script execution
Last modified: 2024-01-12 15:35:47 UTC
CRD: 2023-12-10 although reporter might publish on Dec 6th or 7th.
now public CVE-2023-6186: https://www.cve.org/CVERecord?id=CVE-2023-6186 https://www.libreoffice.org/about-us/security/advisories/cve-2023-6186: https://www.libreoffice.org/about-us/security/advisories/cve-2023-6186 rh#2254005: https://bugzilla.redhat.com/show_bug.cgi?id=2254005
SUSE-SU-2023:4932-1: An update that solves two vulnerabilities can now be installed. Category: security (important) Bug References: 1217577, 1217578 CVE References: CVE-2023-6185, CVE-2023-6186 Sources used: openSUSE Leap 15.4 (src): libreoffice-7.6.2.1-150400.17.20.1 openSUSE Leap 15.5 (src): libreoffice-7.6.2.1-150400.17.20.1 SUSE Package Hub 15 15-SP4 (src): libreoffice-7.6.2.1-150400.17.20.1 SUSE Package Hub 15 15-SP5 (src): libreoffice-7.6.2.1-150400.17.20.1 SUSE Linux Enterprise Workstation Extension 15 SP4 (src): libreoffice-7.6.2.1-150400.17.20.1 SUSE Linux Enterprise Workstation Extension 15 SP5 (src): libreoffice-7.6.2.1-150400.17.20.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
SUSE-SU-2023:4984-1: An update that solves two vulnerabilities can now be installed. Category: security (important) Bug References: 1217577, 1217578 CVE References: CVE-2023-6185, CVE-2023-6186 Sources used: SUSE Linux Enterprise Workstation Extension 12 12-SP5 (src): libreoffice-7.6.2.1-48.51.4 SUSE Linux Enterprise Software Development Kit 12 SP5 (src): libreoffice-7.6.2.1-48.51.4 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.