{"affected":[{"ecosystem_specific":{"binaries":[{"atk-doc":"2.28.1-6.5.23","atk-lang":"2.28.1-6.5.23","libatk-1_0-0":"2.28.1-6.5.23","libatk-1_0-0-32bit":"2.28.1-6.5.23","libxmlsec1-1":"1.2.37-8.6.21","libxmlsec1-gcrypt1":"1.2.37-8.6.21","libxmlsec1-gnutls1":"1.2.37-8.6.21","libxmlsec1-nss1":"1.2.37-8.6.21","libxmlsec1-openssl1":"1.2.37-8.6.21","typelib-1_0-Atk-1_0":"2.28.1-6.5.23","xmlsec1":"1.2.37-8.6.21"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Server for SAP Applications 12 SP4","name":"atk","purl":"pkg:rpm/suse/atk&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP4"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"2.28.1-6.5.23"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"atk-doc":"2.28.1-6.5.23","atk-lang":"2.28.1-6.5.23","libatk-1_0-0":"2.28.1-6.5.23","libatk-1_0-0-32bit":"2.28.1-6.5.23","libxmlsec1-1":"1.2.37-8.6.21","libxmlsec1-gcrypt1":"1.2.37-8.6.21","libxmlsec1-gnutls1":"1.2.37-8.6.21","libxmlsec1-nss1":"1.2.37-8.6.21","libxmlsec1-openssl1":"1.2.37-8.6.21","typelib-1_0-Atk-1_0":"2.28.1-6.5.23","xmlsec1":"1.2.37-8.6.21"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Server for SAP Applications 12 SP4","name":"xmlsec1","purl":"pkg:rpm/suse/xmlsec1&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP4"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"1.2.37-8.6.21"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"atk-doc":"2.28.1-6.5.23","atk-lang":"2.28.1-6.5.23","libatk-1_0-0":"2.28.1-6.5.23","libatk-1_0-0-32bit":"2.28.1-6.5.23","typelib-1_0-Atk-1_0":"2.28.1-6.5.23"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Server 12 SP2-BCL","name":"atk","purl":"pkg:rpm/suse/atk&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP2-BCL"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"2.28.1-6.5.23"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"atk-doc":"2.28.1-6.5.23","atk-lang":"2.28.1-6.5.23","libatk-1_0-0":"2.28.1-6.5.23","libatk-1_0-0-32bit":"2.28.1-6.5.23","libxmlsec1-1":"1.2.37-8.6.21","libxmlsec1-gcrypt1":"1.2.37-8.6.21","libxmlsec1-gnutls1":"1.2.37-8.6.21","libxmlsec1-nss1":"1.2.37-8.6.21","libxmlsec1-openssl1":"1.2.37-8.6.21","typelib-1_0-Atk-1_0":"2.28.1-6.5.23","xmlsec1":"1.2.37-8.6.21"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Server 12 SP4-ESPOS","name":"atk","purl":"pkg:rpm/suse/atk&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP4-ESPOS"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"2.28.1-6.5.23"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"atk-doc":"2.28.1-6.5.23","atk-lang":"2.28.1-6.5.23","libatk-1_0-0":"2.28.1-6.5.23","libatk-1_0-0-32bit":"2.28.1-6.5.23","libxmlsec1-1":"1.2.37-8.6.21","libxmlsec1-gcrypt1":"1.2.37-8.6.21","libxmlsec1-gnutls1":"1.2.37-8.6.21","libxmlsec1-nss1":"1.2.37-8.6.21","libxmlsec1-openssl1":"1.2.37-8.6.21","typelib-1_0-Atk-1_0":"2.28.1-6.5.23","xmlsec1":"1.2.37-8.6.21"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Server 12 SP4-ESPOS","name":"xmlsec1","purl":"pkg:rpm/suse/xmlsec1&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP4-ESPOS"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"1.2.37-8.6.21"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"atk-doc":"2.28.1-6.5.23","atk-lang":"2.28.1-6.5.23","libatk-1_0-0":"2.28.1-6.5.23","libatk-1_0-0-32bit":"2.28.1-6.5.23","libxmlsec1-1":"1.2.37-8.6.21","libxmlsec1-gcrypt1":"1.2.37-8.6.21","libxmlsec1-gnutls1":"1.2.37-8.6.21","libxmlsec1-nss1":"1.2.37-8.6.21","libxmlsec1-openssl1":"1.2.37-8.6.21","typelib-1_0-Atk-1_0":"2.28.1-6.5.23","xmlsec1":"1.2.37-8.6.21"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Server 12 SP4-LTSS","name":"atk","purl":"pkg:rpm/suse/atk&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP4-LTSS"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"2.28.1-6.5.23"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"atk-doc":"2.28.1-6.5.23","atk-lang":"2.28.1-6.5.23","libatk-1_0-0":"2.28.1-6.5.23","libatk-1_0-0-32bit":"2.28.1-6.5.23","libxmlsec1-1":"1.2.37-8.6.21","libxmlsec1-gcrypt1":"1.2.37-8.6.21","libxmlsec1-gnutls1":"1.2.37-8.6.21","libxmlsec1-nss1":"1.2.37-8.6.21","libxmlsec1-openssl1":"1.2.37-8.6.21","typelib-1_0-Atk-1_0":"2.28.1-6.5.23","xmlsec1":"1.2.37-8.6.21"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Server 12 SP4-LTSS","name":"xmlsec1","purl":"pkg:rpm/suse/xmlsec1&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP4-LTSS"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"1.2.37-8.6.21"}],"type":"ECOSYSTEM"}]}],"aliases":[],"details":"This update for LibreOffice fixes the following issues:\n    \nlibreoffice:\n\n- Version update from 7.3.6.2 to 7.5.4.1 (jsc#PED-3561, jsc#PED-3550, jsc#PED-1785):\n  * For the highlights of changes of version 7.5 please consult the official release notes:\n    https://wiki.documentfoundation.org/ReleaseNotes/7.5\n  * For the highlights of changes of version 7.4 please consult the official release notes:\n    https://wiki.documentfoundation.org/ReleaseNotes/7.4\n  * Security issues fixed:\n    + CVE-2023-0950: Fixed stack underflow in ScInterpreter (bsc#1209242)\n    + CVE-2023-2255: Fixed vulnerability where remote documents could be loaded without prompt via IFrame (bsc#1211746)\n  * Bug fixes:\n    + Fix PPTX shadow effect for table offset (bsc#1204040)\n    + Fix ability to set the default tab size for each text object (bsc#1198666)\n    + Fix PPTX extra vertical space between different text formats (bsc#1200085)\n    + Do not use binutils-gold as the package is unmaintainedd and will be removed in the future (bsc#1210687)\n  * Updated bundled dependencies:    \n    * boost version update from 1_77_0 to 1_80_0\n    * curl version update from 7.83.1 to 8.0.1\n    * icu4c-data version update from 70_1 to 72_1\n    * icu4c version update from 70_1 to 72_1\n    * pdfium version update from 4699 to 5408\n    * poppler version update from 21.11.0 to 22.12.0\n    * poppler-data version update from 0.4.10 to 0.4.11\n    * skia version from m97-a7230803d64ae9d44f4e128244480111a3ae967 to m103-b301ff025004c9cd82816c86c547588e6c24b466    \n  * New build dependencies:\n    * fixmath-devel\n    * libwebp-devel\n    * zlib-devel\n    * dragonbox-devel\n    * at-spi2-core-devel\n    * libtiff-devel\n\ndragonbox:\n\n- New package at version 1.1.3 (jsc#PED-1785)\n    * New dependency for LibreOffice 7.4\n\nfixmath:\n\n- New package at version 2022.07.20 (jsc#PED-1785)\n    * New dependency for LibreOffice 7.4\n\nlibmwaw:\n\n- Version update from 0.3.20 to 0.3.21 (jsc#PED-1785):\n  * Add debug code to read some private rsrc data\n  * Allow to read some MacWrite which does not have printer informations\n  * Add a parser for Scoop files\n  * Add a parser for ScriptWriter files\n  * Add a parser for ReadySetGo 1-4 files\n\nxmlsec1:\n    \n- Version update from 1.2.28 to 1.2.37 required by LibreOffice 7.5.2.2 (jsc#PED-3561, jsc#PED-3550):\n  * Retired the XMLSec mailing list 'xmlsec@aleksey.com' and the XMLSec Online Signature Verifier.\n  * Migration to OpenSSL 3.0 API Note that OpenSSL engines are disabled by default when XMLSec library is compiled\n    against OpenSSL 3.0.\n    To re-enable OpenSSL engines, use `--enable-openssl3-engines` configure flag \n    (there will be a lot of deprecation warnings).\n  * The OpenSSL before 1.1.0 and LibreSSL before 2.7.0 are now deprecated and will be removed in the future versions of\n    XMLSec Library.\n  * Refactored all the integer casts to ensure cast-safety. Fixed all warnings and enabled `-Werror` and `-pedantic` \n    flags on CI builds.\n  * Added configure flag to use size_t for xmlSecSize (currently disabled by default for backward compatibility).\n  * Support for OpenSSL compiled with OPENSSL_NO_ERR.\n  * Full support for LibreSSL 3.5.0 and above\n  * Several other small fixes\n  * Fix decrypting session key for two recipients \n  * Added `--privkey-openssl-engine` option to enhance openssl engine support\n  * Remove MD5 for NSS 3.59 and above\n  * Fix PKCS12_parse return code handling\n  * Fix OpenSSL lookup\n  * xmlSecX509DataGetNodeContent(): don't return 0 for non-empty elements - fix for LibreOffice\n  * Unload error strings in OpenSSL shutdown.\n  * Make userData available when executing preExecCallback function\n  * Add an option to use secure memset.\n  * Enabled XML_PARSE_HUGE for all xml parsers.\n  * Various build and tests fixes and improvements.\n  * Move remaining private header files away from xmlsec/include/`` folder\n- Other packaging changes:\n  * Relax the crypto policies for the test-suite. It allows the tests using certificates with small key lengths to pass.\n  * Pass `--disable-md5` to configure: The cryptographic strength of the MD5 algorithm is sufficiently doubtful that its\n    use is discouraged at this time. It is not listed as an algorithm in [XMLDSIG-CORE1]\n    https://www.w3.org/TR/xmlsec-algorithms/#bib-XMLDSIG-CORE1\n","id":"SUSE-FU-2023:3696-1","modified":"2023-09-20T07:56:44Z","published":"2023-09-20T07:56:44Z","references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/-2023-3696/suse-fu-20233696-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1198666"},{"type":"REPORT","url":"https://bugzilla.suse.com/1200085"},{"type":"REPORT","url":"https://bugzilla.suse.com/1204040"},{"type":"REPORT","url":"https://bugzilla.suse.com/1209242"},{"type":"REPORT","url":"https://bugzilla.suse.com/1210687"},{"type":"REPORT","url":"https://bugzilla.suse.com/1211746"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-0950"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-2255"}],"related":["CVE-2023-0950","CVE-2023-2255"],"summary":"Feature update for LibreOffice","upstream":["CVE-2023-0950","CVE-2023-2255"]}