Security Bulletin
This security bulletin contains one high risk vulnerability.
EUVDB-ID: #VU89492
Risk: High
CVSSv3.1: 7.7 [CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C]
CVE-ID: CVE-2024-3044
CWE-ID:
CWE-254 - Security Features
Exploit availability: No
DescriptionThe vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to a missing check for lick events on graphics. A remote attacker can trick the victim to open a specially crafted document and execute arbitrary macro on the system.
Update the affected package libreoffice to the latest version.
Vulnerable software versionsSUSE Linux Enterprise Workstation Extension 15: SP5 - SP6
SUSE Package Hub 15: 15-SP5 - 15-SP6
SUSE Linux Enterprise Real Time 15: SP5 - SP6
openSUSE Leap: 15.5 - 15.6
SUSE Linux Enterprise Server for SAP Applications 15: SP5 - SP6
SUSE Linux Enterprise Server 15: SP5 - SP6
SUSE Linux Enterprise Desktop 15: SP5 - SP6
SUSE Linux Enterprise Micro: 5.5
SUSE Linux Enterprise High Performance Computing 15: SP5
libreoffice-l10n-sr: before 24.2.4.2-150500.20.6.5
libreoffice-l10n-ca_valencia: before 24.2.4.2-150500.20.6.5
libreoffice-l10n-fa: before 24.2.4.2-150500.20.6.5
libreoffice-l10n-mr: before 24.2.4.2-150500.20.6.5
libreoffice-l10n-be: before 24.2.4.2-150500.20.6.5
libreoffice-l10n-bo: before 24.2.4.2-150500.20.6.5
libreoffice-l10n-lt: before 24.2.4.2-150500.20.6.5
libreoffice-l10n-ks: before 24.2.4.2-150500.20.6.5
libreoffice-l10n-ug: before 24.2.4.2-150500.20.6.5
libreoffice-l10n-en_ZA: before 24.2.4.2-150500.20.6.5
libreoffice-l10n-th: before 24.2.4.2-150500.20.6.5
libreoffice-l10n-dz: before 24.2.4.2-150500.20.6.5
libreoffice-l10n-ar: before 24.2.4.2-150500.20.6.5
libreoffice-l10n-cs: before 24.2.4.2-150500.20.6.5
libreoffice-l10n-cy: before 24.2.4.2-150500.20.6.5
libreoffice-l10n-sid: before 24.2.4.2-150500.20.6.5
libreoffice-l10n-am: before 24.2.4.2-150500.20.6.5
libreoffice-l10n-bn: before 24.2.4.2-150500.20.6.5
libreoffice-l10n-pt_PT: before 24.2.4.2-150500.20.6.5
libreoffice-l10n-nb: before 24.2.4.2-150500.20.6.5
libreoffice-l10n-uz: before 24.2.4.2-150500.20.6.5
libreoffice-l10n-sk: before 24.2.4.2-150500.20.6.5
libreoffice-l10n-fi: before 24.2.4.2-150500.20.6.5
libreoffice-l10n-fy: before 24.2.4.2-150500.20.6.5
libreoffice-l10n-sl: before 24.2.4.2-150500.20.6.5
libreoffice-l10n-kab: before 24.2.4.2-150500.20.6.5
libreoffice-l10n-hsb: before 24.2.4.2-150500.20.6.5
libreoffice-l10n-nr: before 24.2.4.2-150500.20.6.5
libreoffice-l10n-ro: before 24.2.4.2-150500.20.6.5
libreoffice-l10n-hi: before 24.2.4.2-150500.20.6.5
libreoffice-l10n-kmr_Latn: before 24.2.4.2-150500.20.6.5
libreoffice-l10n-et: before 24.2.4.2-150500.20.6.5
libreoffice-l10n-el: before 24.2.4.2-150500.20.6.5
libreoffice-l10n-ja: before 24.2.4.2-150500.20.6.5
libreoffice-l10n-br: before 24.2.4.2-150500.20.6.5
libreoffice-icon-themes: before 24.2.4.2-150500.20.6.5
libreoffice-l10n-sat: before 24.2.4.2-150500.20.6.5
libreoffice-l10n-hu: before 24.2.4.2-150500.20.6.5
libreoffice-l10n-mk: before 24.2.4.2-150500.20.6.5
libreoffice-l10n-hy: before 24.2.4.2-150500.20.6.5
libreoffice-l10n-zh_TW: before 24.2.4.2-150500.20.6.5
libreoffice-l10n-rw: before 24.2.4.2-150500.20.6.5
libreoffice-glade: before 24.2.4.2-150500.20.6.5
libreoffice-l10n-en: before 24.2.4.2-150500.20.6.5
libreoffice-l10n-mni: before 24.2.4.2-150500.20.6.5
libreoffice-l10n-tt: before 24.2.4.2-150500.20.6.5
libreoffice-l10n-km: before 24.2.4.2-150500.20.6.5
libreoffice-l10n-lv: before 24.2.4.2-150500.20.6.5
libreoffice-l10n-hr: before 24.2.4.2-150500.20.6.5
libreoffice-l10n-da: before 24.2.4.2-150500.20.6.5
libreoffice-l10n-lb: before 24.2.4.2-150500.20.6.5
libreoffice-l10n-ss: before 24.2.4.2-150500.20.6.5
libreoffice-l10n-or: before 24.2.4.2-150500.20.6.5
libreoffice-l10n-ca: before 24.2.4.2-150500.20.6.5
libreoffice-l10n-pa: before 24.2.4.2-150500.20.6.5
libreoffice-l10n-he: before 24.2.4.2-150500.20.6.5
libreoffice-l10n-st: before 24.2.4.2-150500.20.6.5
libreoffice-l10n-sa_IN: before 24.2.4.2-150500.20.6.5
libreoffice-l10n-de: before 24.2.4.2-150500.20.6.5
libreoffice-l10n-ka: before 24.2.4.2-150500.20.6.5
libreoffice-l10n-gu: before 24.2.4.2-150500.20.6.5
libreoffice-l10n-ve: before 24.2.4.2-150500.20.6.5
libreoffice-l10n-tn: before 24.2.4.2-150500.20.6.5
libreoffice-l10n-mai: before 24.2.4.2-150500.20.6.5
libreoffice-l10n-id: before 24.2.4.2-150500.20.6.5
libreoffice-l10n-nn: before 24.2.4.2-150500.20.6.5
libreoffice-l10n-om: before 24.2.4.2-150500.20.6.5
libreoffice-l10n-sw_TZ: before 24.2.4.2-150500.20.6.5
libreoffice-l10n-ckb: before 24.2.4.2-150500.20.6.5
libreoffice-l10n-fur: before 24.2.4.2-150500.20.6.5
libreoffice-l10n-is: before 24.2.4.2-150500.20.6.5
libreoffice-l10n-mn: before 24.2.4.2-150500.20.6.5
libreoffice-l10n-my: before 24.2.4.2-150500.20.6.5
libreoffice-l10n-bg: before 24.2.4.2-150500.20.6.5
libreoffice-l10n-es: before 24.2.4.2-150500.20.6.5
libreoffice-l10n-ts: before 24.2.4.2-150500.20.6.5
libreoffice-l10n-tg: before 24.2.4.2-150500.20.6.5
libreoffice-l10n-nso: before 24.2.4.2-150500.20.6.5
libreoffice-l10n-dsb: before 24.2.4.2-150500.20.6.5
libreoffice-l10n-vec: before 24.2.4.2-150500.20.6.5
libreoffice-l10n-gl: before 24.2.4.2-150500.20.6.5
libreoffice-l10n-tr: before 24.2.4.2-150500.20.6.5
libreoffice-l10n-vi: before 24.2.4.2-150500.20.6.5
libreoffice-l10n-dgo: before 24.2.4.2-150500.20.6.5
libreoffice-gdb-pretty-printers: before 24.2.4.2-150500.20.6.5
libreoffice-l10n-af: before 24.2.4.2-150500.20.6.5
libreoffice-l10n-sv: before 24.2.4.2-150500.20.6.5
libreoffice-l10n-ne: before 24.2.4.2-150500.20.6.5
libreoffice-l10n-oc: before 24.2.4.2-150500.20.6.5
libreoffice-l10n-ta: before 24.2.4.2-150500.20.6.5
libreoffice-l10n-as: before 24.2.4.2-150500.20.6.5
libreoffice-l10n-gd: before 24.2.4.2-150500.20.6.5
libreoffice-l10n-zu: before 24.2.4.2-150500.20.6.5
libreoffice-l10n-ast: before 24.2.4.2-150500.20.6.5
libreoffice-l10n-uk: before 24.2.4.2-150500.20.6.5
libreoffice-l10n-eu: before 24.2.4.2-150500.20.6.5
libreoffice-l10n-xh: before 24.2.4.2-150500.20.6.5
libreoffice-l10n-nl: before 24.2.4.2-150500.20.6.5
libreoffice-l10n-ko: before 24.2.4.2-150500.20.6.5
libreoffice-l10n-brx: before 24.2.4.2-150500.20.6.5
libreoffice-l10n-kok: before 24.2.4.2-150500.20.6.5
libreoffice-l10n-szl: before 24.2.4.2-150500.20.6.5
libreoffice-l10n-kn: before 24.2.4.2-150500.20.6.5
libreoffice-l10n-pl: before 24.2.4.2-150500.20.6.5
libreoffice-l10n-si: before 24.2.4.2-150500.20.6.5
libreoffice-l10n-lo: before 24.2.4.2-150500.20.6.5
libreoffice-branding-upstream: before 24.2.4.2-150500.20.6.5
libreoffice-l10n-ml: before 24.2.4.2-150500.20.6.5
libreoffice-l10n-it: before 24.2.4.2-150500.20.6.5
libreoffice-l10n-te: before 24.2.4.2-150500.20.6.5
libreoffice-l10n-bn_IN: before 24.2.4.2-150500.20.6.5
libreoffice-l10n-bs: before 24.2.4.2-150500.20.6.5
libreoffice-l10n-ru: before 24.2.4.2-150500.20.6.5
libreoffice-l10n-pt_BR: before 24.2.4.2-150500.20.6.5
libreoffice-l10n-sq: before 24.2.4.2-150500.20.6.5
libreoffice-l10n-sd: before 24.2.4.2-150500.20.6.5
libreoffice-l10n-en_GB: before 24.2.4.2-150500.20.6.5
libreoffice-l10n-zh_CN: before 24.2.4.2-150500.20.6.5
libreoffice-l10n-gug: before 24.2.4.2-150500.20.6.5
libreoffice-l10n-eo: before 24.2.4.2-150500.20.6.5
libreoffice-l10n-ga: before 24.2.4.2-150500.20.6.5
libreoffice-l10n-kk: before 24.2.4.2-150500.20.6.5
libreoffice-l10n-fr: before 24.2.4.2-150500.20.6.5
libreoffice-impress-debuginfo: before 24.2.4.2-150500.20.6.5
libreoffice-sdk-debuginfo: before 24.2.4.2-150500.20.6.5
libreoffice-officebean: before 24.2.4.2-150500.20.6.5
libreoffice-writer: before 24.2.4.2-150500.20.6.5
libreoffice-writer-debuginfo: before 24.2.4.2-150500.20.6.5
libreoffice-gnome: before 24.2.4.2-150500.20.6.5
libreofficekit: before 24.2.4.2-150500.20.6.5
libreoffice-impress: before 24.2.4.2-150500.20.6.5
libreoffice-calc: before 24.2.4.2-150500.20.6.5
libreoffice-sdk-doc: before 24.2.4.2-150500.20.6.5
libreoffice-base-debuginfo: before 24.2.4.2-150500.20.6.5
libreoffice-gtk3-debuginfo: before 24.2.4.2-150500.20.6.5
libreoffice-debugsource: before 24.2.4.2-150500.20.6.5
libreoffice-draw: before 24.2.4.2-150500.20.6.5
libreoffice-base-drivers-postgresql: before 24.2.4.2-150500.20.6.5
libreoffice-draw-debuginfo: before 24.2.4.2-150500.20.6.5
libreoffice-calc-debuginfo: before 24.2.4.2-150500.20.6.5
libreoffice-pyuno: before 24.2.4.2-150500.20.6.5
libreoffice-officebean-debuginfo: before 24.2.4.2-150500.20.6.5
libreoffice-librelogo: before 24.2.4.2-150500.20.6.5
libreoffice: before 24.2.4.2-150500.20.6.5
libreoffice-pyuno-debuginfo: before 24.2.4.2-150500.20.6.5
libreoffice-mailmerge: before 24.2.4.2-150500.20.6.5
libreoffice-math: before 24.2.4.2-150500.20.6.5
libreoffice-debuginfo: before 24.2.4.2-150500.20.6.5
libreoffice-base-drivers-postgresql-debuginfo: before 24.2.4.2-150500.20.6.5
libreofficekit-devel: before 24.2.4.2-150500.20.6.5
libreoffice-sdk: before 24.2.4.2-150500.20.6.5
libreoffice-qt5-debuginfo: before 24.2.4.2-150500.20.6.5
libreoffice-gtk3: before 24.2.4.2-150500.20.6.5
libreoffice-calc-extensions: before 24.2.4.2-150500.20.6.5
libreoffice-qt5: before 24.2.4.2-150500.20.6.5
libreoffice-math-debuginfo: before 24.2.4.2-150500.20.6.5
libreoffice-base: before 24.2.4.2-150500.20.6.5
libreoffice-gnome-debuginfo: before 24.2.4.2-150500.20.6.5
libreoffice-filters-optional: before 24.2.4.2-150500.20.6.5
libreoffice-writer-extensions: before 24.2.4.2-150500.20.6.5
CPE2.3http://www.suse.com/support/update/announcement/2024/suse-su-20242257-1/
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.