[Git][security-tracker-team/security-tracker][master] new libreoffice issues
Moritz Muehlenhoff (@jmm)
jmm at debian.org
Tue Sep 22 22:12:44 BST 2026
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker
Commits:
8fe49e14 by Moritz Muehlenhoff at 2026-09-22T23:11:42+02:00
new libreoffice issues
- - - - -
2 changed files:
- data/CVE/list
- data/dsa-needed.txt
Changes:
=====================================
data/CVE/list
=====================================
@@ -525,19 +525,26 @@ CVE-2026-65111 (NVIDIA NeMo Speech for all platforms contains a vulnerability wh
CVE-2026-63386 (js-toml is a TOML parser for JavaScript. Prior to 1.1.3, load() does n ...)
TODO: check
CVE-2026-63279 (LibreOffice can import PICT images, which may be embedded in documents ...)
- TODO: check
+ - libreoffice 4:26.2.5.2-1
+ NOTE: https://www.libreoffice.org/security/#cve-2026-63279
CVE-2026-63278 (URLs could be constructed which expanded environment variable or INI f ...)
- TODO: check
+ - libreoffice 4:26.2.5.2-1
+ NOTE: https://www.libreoffice.org/security/#cve-2026-63278
CVE-2026-63276 (LibreOffice converts CFF fonts to Type 1 when it subsets a font, which ...)
- TODO: check
+ - libreoffice 4:26.2.5.2-1
+ NOTE: https://www.libreoffice.org/security/#cve-2026-63276
CVE-2026-63275 (LibreOffice can read CFF fonts, which may be embedded in documents. A ...)
- TODO: check
+ - libreoffice 4:26.2.5.2-1
+ NOTE: https://www.libreoffice.org/security/#cve-2026-63275
CVE-2026-63274 (LibreOffice Draw can import PDF documents. A heap buffer overflow exis ...)
- TODO: check
+ - libreoffice 4:26.2.5.2-1
+ NOTE: https://www.libreoffice.org/security/#cve-2026-63274
CVE-2026-63273 (LibreOffice Draw can import PDF documents. A heap buffer overflow exis ...)
- TODO: check
+ - libreoffice 4:26.2.5.2-1
+ NOTE: https://www.libreoffice.org/security/#cve-2026-63273
CVE-2026-63272 (LibreOffice can import WMF graphics, which may be embedded in document ...)
- TODO: check
+ - libreoffice 4:26.2.5.2-1
+ NOTE: https://www.libreoffice.org/security/#cve-2026-63272
CVE-2026-57149 (plone.app.portlets.portlets provides a Plone-specific user interface f ...)
TODO: check
CVE-2026-56682 (9Router is an AI router & token saver. Prior to 0.5.6, 9Router deploym ...)
=====================================
data/dsa-needed.txt
=====================================
@@ -78,6 +78,8 @@ kitty
libheif (aron)
Wait until new upstream release lands in sid
--
+libreoffice
+--
linux (carnil)
Wait until more issues have piled up, though try to regulary rebase for point
releases to more 6.12.y versions
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/8fe49e149f20b95a9e797e219220f7139919fc36
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/8fe49e149f20b95a9e797e219220f7139919fc36
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260922/30eb1467/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list