File _patchinfo of Package patchinfo.11409

<patchinfo incident="11409">
  <issue tracker="bnc" id="882383">LO-L3: Chart in PPTX lacks color and is too large</issue>
  <issue tracker="bnc" id="1135189">[Build 20190515-1] LibreOffice requires JRE which is not installed for unknown reason</issue>
  <issue tracker="bnc" id="1124658">SLED15 : libreoffice in SLE 15  impossible to use with pictures</issue>
  <issue tracker="bnc" id="1123131">libreoffice: KDE UI</issue>
  <issue tracker="bnc" id="1123455">[Build 20190126] openQA test fails in libreoffice_recent_documents</issue>
  <issue tracker="bnc" id="1127857">libreoffice fails to build against devel:gcc</issue>
  <issue tracker="bnc" id="1110348">[PPTX] Charts having weird/darker/ugly background versus Office 365 and strange artefacts where overlapping</issue>
  <issue tracker="bnc" id="1112112">[PPTX] SmartArt: Basic rendering of several list types</issue>
  <issue tracker="bnc" id="1117195">LibreOfficeKit header file missing</issue>
  <issue tracker="bnc" id="1116451">Use new help system for libreoffice</issue>
  <issue tracker="bnc" id="1128845">Libreoffice 6.2.1 VCL kde5 copy paste broken</issue>
  <issue tracker="bnc" id="1117300">[DATA LOSS] Saving a new document can silently overwrite an existing document</issue>
  <issue tracker="bnc" id="1124062">VUL-0: CVE-2018-16858: libreoffice: InsertScript: Remote Code Execution via Macro/Event execution</issue>
  <issue tracker="bnc" id="1135228">LO-L3: PPTX: Rectangle turns from green to blue and loses transparency when transparency is set</issue>
  <issue tracker="bnc" id="1127760">Slide deck compression doesn't, hmm, compress too much</issue>
  <issue tracker="bnc" id="1124869">Psychedelic graphics in LibreOffice (but not PowerPoint)</issue>
  <issue tracker="bnc" id="1112114">[PPTX] SmartArt: Basic rendering of the Organizational Chart</issue>
  <issue tracker="bnc" id="1121874">Image from PPTX shown in a square, not a circle</issue>
  <issue tracker="bnc" id="1112113">[PPTX] SmartArt: Basic rendering of Accent Process and Continuous Block Process</issue>
  <issue tracker="cve" id="2018-16858"/>
  <issue tracker="fate" id="327121"/>
  <category>security</category>
  <rating>important</rating>
  <packager>scarabeus_iv</packager>
  <description>This update for libreoffice fixes the following issues:

LibreOffice was updated to 6.2.5.2 (fate#327121).

Security issue fixed:

- CVE-2018-16858: LibreOffice was vulnerable to a directory traversal attack which could be used to execute arbitrary macros bundled with a document. An attacker could craft a document, which when opened by LibreOffice, would execute a Python method from a script in any arbitrary file system location, specified relative to the LibreOffice install location. (bsc#1124062)

Other bugfixes:

- If there is no firebird engine we still need java to run hsqldb (bsc#1135189)
- Require firebird as default driver for base if enabled
- PPTX: Rectangle turns from green to blue and loses transparency when transparency is set (bsc1135228)
- Slide deck compression doesn't, hmm, compress too much (bsc#1127760)
- Psychedelic graphics in LibreOffice (but not PowerPoint) (bsc#1124869)
- Image from PPTX shown in a square, not a circle (bsc#1121874)
- Switch to the new web based help system bsc#1116451
- Enable new approach for mariadb connector again
- PPTX: SmartArt: Basic rendering of the Organizational Chart (bsc#1112114)
- PPTX: SmartArt: Basic rendering of Accent Process and Continuous Block Process (bsc#1112113)
- Saving a new document can silently overwrite an existing document (bsc#1117300)
- Install also C++ libreofficekit headers bsc#1117195
- Chart in PPTX lacks color and is too large (bsc#882383)
- PPTX: SmartArt: Basic rendering of several list types (bsc#1112112)
- PPTX: Charts having weird/darker/ugly background versus Office 365 and strange artefacts where overlapping (bsc#1110348)

</description>
  <summary>Security update for libreoffice</summary>
</patchinfo>
openSUSE Build Service is sponsored by