This script is Copyright (C) 2015 Tenable Network Security, Inc.
The remote Scientific Linux host is missing one or more security
It was found that LibreOffice documents executed macros
unconditionally, without user approval, when these documents were
opened using LibreOffice. An attacker could use this flaw to execute
arbitrary code as the user running LibreOffice by embedding malicious
VBA scripts in the document as macros. (CVE-2014-0247)
A flaw was found in the OLE (Object Linking and Embedding) generation
in LibreOffice. An attacker could use this flaw to embed malicious OLE
code in a LibreOffice document, allowing for arbitrary code execution.
A use-after-free flaw was found in the 'Remote Control' capabilities
of the LibreOffice Impress application. An attacker could use this
flaw to remotely execute code with the permissions of the user running
LibreOffice Impress. (CVE-2014-3693)
The libreoffice packages have been upgraded to upstream version
188.8.131.52, which provides a number of bug fixes and enhancements over
the previous version. Among others :
- Improved OpenXML interoperability.
- Additional statistic functions in Calc (for
interoperability with Excel and Excel's Add-in 'Analysis
- Various performance improvements in Calc.
- Apple Keynote and Abiword import.
- Improved MathML export.
- New Start screen with thumbnails of recently opened
- Visual clue in Slide Sorter when a slide has a
transition or an animation.
- Improvements for trend lines in charts.
- Support for BCP-47 language tags.
See also :
Update the affected packages.
Risk factor :
Critical / CVSS Base Score : 10.0