MGASA-2014-0446

Source
https://advisories.mageia.org/MGASA-2014-0446.html
Import Source
https://advisories.mageia.org/MGASA-2014-0446.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2014-0446
Upstream
  • CVE-2014-3575
Published
2014-11-14T01:24:42Z
Modified
2026-04-16T06:26:25.116209130Z
Summary
Updated libreoffice packages fix security vulnerability
Details

A vulnerability in LibreOffice allows an attacker to send a document which when opened will trigger the prompt to "Update Links" but if the user cancels that prompt may still generate and insert into the document an OLE2 preview image of a file on the victims filesystem, Data exposure is possible if the updated document is then distributed to other parties (CVE-2014-3575).

LibreOffice has been patched to fix this issue.

References
Credits

Affected packages

Mageia:3 / libreoffice

Package

Name
libreoffice
Purl
pkg:rpm/mageia/libreoffice?arch=source&distro=mageia-3

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.0.6.2-3.mga3

Ecosystem specific

{
    "section": "core"
}

Database specific

source
"https://advisories.mageia.org/MGASA-2014-0446.json"