ECHO-0c5b-b878-d4d7

See a problem?
Import Source
https://advisory.echohq.com/osv/ECHO-0c5b-b878-d4d7.json
JSON Data
https://api.osv.dev/v1/vulns/ECHO-0c5b-b878-d4d7
Upstream
Withdrawn
2026-09-29T11:00:03Z
Published
2026-04-20T21:16:23Z
Modified
2026-09-29T11:45:37Z
Summary
Not a vulnerability in LibreOffice itself. The report is that documents can embed or link external content that LibreOffice opens automatically, which is documented, expected behaviour of the OpenDocument format rather than a memory-safety or logic bug. Upstream treated it as a UI/hardening improvement request (fdo#58295). Debian classifies it as unimportant ("Additional hardening/UI improvement, not a direct vulnerability") and has left it unfixed in every release. No code change is required. https://security-tracker.debian.org/tracker/CVE-2012-5639
Details
References

Affected packages

Echo / libreoffice

Package

Name
libreoffice
Purl
pkg:deb/echo/libreoffice

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
4:25.2.3-2+deb13u6

Database specific

source
"https://advisory.echohq.com/osv/ECHO-0c5b-b878-d4d7.json"