Not a vulnerability in LibreOffice itself. The report is that documents
can embed or link external content that LibreOffice opens automatically,
which is documented, expected behaviour of the OpenDocument format rather
than a memory-safety or logic bug. Upstream treated it as a UI/hardening
improvement request (fdo#58295). Debian classifies it as unimportant
("Additional hardening/UI improvement, not a direct vulnerability") and
has left it unfixed in every release. No code change is required.
https://security-tracker.debian.org/tracker/CVE-2012-5639