File _patchinfo of Package patchinfo.6982
<patchinfo incident="6982">
<issue id="976831" tracker="bnc">Highlighted Text not exported into PDF</issue>
<issue id="975283" tracker="bnc">Slide background messed up after import from pptx</issue>
<issue id="962777" tracker="bnc">Some slides are missing their contents</issue>
<issue id="948058" tracker="bnc">Black rectangles instead of graphics for PPTX - in presentation mode only</issue>
<issue id="1021373" tracker="bnc">Saving ODP document as PPTX and then reopening causes loss of content</issue>
<issue id="1021369" tracker="bnc">Saving ODP document as PPTX and then reopening causes changes of vertical distance between items</issue>
<issue id="1015360" tracker="bnc">Saving ODP document as PPTX and then reopening causes several changes</issue>
<issue id="1015118" tracker="bnc">LO Impress: some elements not visible</issue>
<issue id="1015115" tracker="bnc">LO Impress: chart labels misplaced</issue>
<issue id="972777" tracker="bnc">Graphics in PPTX shown incorrectly / too small</issue>
<issue id="959926" tracker="bnc">Text not rotated properly in LO Impress tables</issue>
<issue id="1035087" tracker="bnc">openQA test fails in oomath - language could not be detected</issue>
<issue id="1028817" tracker="bnc">gnome-documents crashed and dumped core</issue>
<issue id="1017925" tracker="bnc">LibreOffice demands libobdc.so.1 but unixOBDC only provids libobdc.so.2</issue>
<issue id="1042828" tracker="bnc">CVE-2017-9433: libmwaw out-of-bounds write</issue>
<issue id="1036975" tracker="bnc">CVE-2017-8358: libreoffice: heap-based buffer overflow related to the ReadJPEG function in vcl/source/filter/jpeg/jpegc.cxx</issue>
<issue id="1034329" tracker="bnc">CVE-2017-7882: libreoffice: out-of-bounds write (HWPFile::TagsRead function in hwpfilter/source/hwpfile.cxx)</issue>
<issue id="1034568" tracker="bnc">CVE-2017-7870: libreoffice: LibreOffice before 2017-01-02 has an out-of-bounds write caused by a heap-basedbuffer overflow rela...</issue>
<issue id="1034192" tracker="bnc">CVE-2016-10327: libreoffice: heap-based buffer overflow (EnhWMFReader::ReadEnhWMF function in vcl/source/filter/wmf/enhwmf.cxx)</issue>
<issue id="2017-7870" tracker="cve" />
<issue id="2017-7882" tracker="cve" />
<issue id="2017-8358" tracker="cve" />
<issue id="2017-9433" tracker="cve" />
<issue id="2016-10327" tracker="cve" />
<issue id="323270" tracker="fate" />
<issue id="318572" tracker="fate" />
<issue id="322101" tracker="fate" />
<category>security</category>
<rating>moderate</rating>
<packager>leonardocf</packager>
<summary>Security update for libreoffice</summary>
<description>
LibreOffice was updated to version 5.3.3.2, bringing new features and enhancements:
Writer:
- New "Go to Page" dialog for quickly jumping to another page.
- Support for "Table Styles".
- New drawing tools were added.
- Improvements in the toolbar.
- Borderless padding is displayed.
Calc:
- New drawing tools were added.
- In new installations the default setting for new documents is now "Enable wildcards in formulas"
instead of regular expressions.
- Improved compatibility with ODF 1.2
Impress:
- Images inserted via "Photo Album" can now be linked instead of embedded in the document.
- When launching Impress, a Template Selector allows you to choose a Template to start with.
- Two new default templates: Vivid and Pencil.
- All existing templates have been improved.
Draw:
- New arrow endings, including Crow's foot notation's ones.
Base:
- Firebird has been upgraded to version 3.0.0. It is unable to read back Firebird 2.5 data,
so embedded Firebird odb files created in LibreOffice version up to 5.2 cannot be opened
with LibreOffice 5.3.
Some security issues have also been fixed:
- CVE-2017-7870: An out-of-bounds write caused by a heap-based buffer overflow related to
the tools::Polygon::Insert function.
- CVE-2017-7882: An out-of-bounds write related to the HWPFile::TagsRead function.
- CVE-2017-8358: an out-of-bounds write caused by a heap-based buffer overflow related to
the ReadJPEG function.
- CVE-2016-10327: An out-of-bounds write caused by a heap-based buffer overflow related to
the EnhWMFReader::ReadEnhWMF function.
- CVE-2017-9433: An out-of-bounds write caused by a heap-based buffer overflow related to
the MsWrd1Parser::readFootnoteCorrespondance function in libmwaw.
A comprehensive list of new features and changes in this release is available at:
https://wiki.documentfoundation.org/ReleaseNotes/5.3
This update was imported from the SUSE:SLE-12:Update update project.</description>
</patchinfo>