Upstream information
Description
LibreOffice 3.5.x before 3.5.7.2 and 3.6.x before 3.6.1, and OpenOffice.org (OOo), allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted (1) odt file to vcllo.dll, (2) ODG (Drawing document) file to svxcorelo.dll, (3) PolyPolygon record in a .wmf (Window Meta File) file embedded in a ppt (PowerPoint) file to tllo.dll, or (4) xls (Excel) file to scfiltlo.dll.NVD CVSS v2 Base Score: 4.3 (AV:N/AC:M/Au:N/C:N/I:N/A:P)
Novell/SUSE information
Novell Bugzilla entry: 778669 SUSE Security Advisories:- openSUSE-SU-2012:1523-1, published Thu, 22 Nov 2012 11:08:31 +0100 (CET)
- openSUSE-SU-2012:1686-1, published Sun, 23 Dec 2012 20:10:55 +0100 (CET)
- openSUSE-SU-2013:0173-1, published Wed, 23 Jan 2013 14:07:02 +0100 (CET)
List of released packages
| Product(s) | Fixed package version(s) | References |
|---|---|---|
| SUSE Linux Enterprise Desktop 10 SP4 for AMD64 and Intel EM64T SUSE Linux Enterprise Desktop 10 SP4 for x86 |
| sle10-sp4-sdk.x86-64 sle10-sp4-sdk.x86 sled10-sp4.x86 sled10-sp4.x86-64 ZYPP Patch Nr: 8286 |
| SLE SDK 10 SP4 for X86-64 SLE SDK 10 SP4 for x86 |
| sle10-sp4-sdk.x86-64 sle10-sp4-sdk.x86 sled10-sp4.x86 sled10-sp4.x86-64 ZYPP Patch Nr: 8286 |
| SUSE Linux Enterprise Software Development Kit 11 SP2 |
| sle11-sp2-sdk.x86 sled11-sp2.x86 sle11-sp2-sdk.x86-64 sle11-sp2-sdk.x86 sled11-sp2.x86-64 sle11-sp2-sdk.x86-64 sled11-sp2.x86 sled11-sp2.x86-64 SAT Patch Nr: 6804 |
| SUSE Linux Enterprise Desktop 11 SP2 |
| sle11-sp2-sdk.x86 sled11-sp2.x86 sle11-sp2-sdk.x86-64 sle11-sp2-sdk.x86 sled11-sp2.x86-64 sle11-sp2-sdk.x86-64 sled11-sp2.x86 sled11-sp2.x86-64 SAT Patch Nr: 6804 |
