Debian 10380 Published by

Debian GNU/Linux has been updated with several security enhancements, including ucf, libreoffice, and snapcast updates.

Debian GNU/Linux 9 (Stretch) and 10 (Buster) Extended LTS:
ELA-1299-1 libreoffice security update

Debian GNU/Linux 11 (Bullseye) LTS:
[DLA 4016-1] ucf security update

Debian GNU/Linux 12 (Bookworm):
[DSA 5847-1] snapcast security update



[SECURITY] [DLA 4016-1] ucf security update


- -------------------------------------------------------------------------
Debian LTS Advisory DLA-4016-1 debian-lts@lists.debian.org
https://www.debian.org/lts/security/ Chris Lamb
January 21, 2025 https://wiki.debian.org/LTS
- -------------------------------------------------------------------------

Package : ucf
Version : 3.0043+deb11u2
Debian Bug : 1089015

It was discovered that there was a potential command-injection
vulnerability was discovered in ucf, a tool to preserve user changes
to config files.

For Debian 11 bullseye, this problem has been fixed in version
3.0043+deb11u2.

We recommend that you upgrade your ucf packages.

For the detailed security status of ucf please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/ucf

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS



ELA-1299-1 libreoffice security update


Package : libreoffice
Version : 1:6.1.5-3+deb9u6 (stretch), 1:6.1.5-3+deb10u15 (buster)

Related CVEs :
CVE-2024-12425
CVE-2024-12426

Libreoffice a office productivity software suite, was affected by two vulnerabilities

CVE-2024-12425
An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability was found
in The Document Foundation LibreOffice and allows Absolute Path Traversal. An attacker can write to arbitrary
locations, albeit suffixed with ".ttf", by supplying a file in a format that supports embedded font files.

CVE-2024-12426
An Exposure of Environmental Variables and arbitrary INI file values to an Unauthorized Actor vulnerability
was found in The Document Foundation LibreOffice. URLs could be constructed which expanded environmental
variables or INI file values, so potentially sensitive information could be exfiltrated
to a remote server on opening a document containing such links.


ELA-1299-1 libreoffice security update



[SECURITY] [DSA 5847-1] snapcast security update


- -------------------------------------------------------------------------
Debian Security Advisory DSA-5847-1 security@debian.org
https://www.debian.org/security/ Moritz Muehlenhoff
January 21, 2025 https://www.debian.org/security/faq
- -------------------------------------------------------------------------

Package : snapcast
CVE ID : CVE-2023-36177

It was discovered that the JSON RPC interface of the server componenent
of Snapcast, a multi-room client-server audio player, allowed the
execution of arbitrary code.

For the stable distribution (bookworm), this problem has been fixed in
version 0.26.0+dfsg1-1+deb12u1.

We recommend that you upgrade your snapcast packages.

For the detailed security status of snapcast please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/snapcast

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/