Gnoppix Security released GSA-6346-1 for LibreOffice. Critical vulnerabilities allow remote code execution. Users must upgrade immediately.
Affected Systems
- Gnoppix 23/25 (old stable) requires upgrade to version 4:7.4.7-1+deb12u1.
- Gnoppix 25 (stable) requires upgrade to the same fixed version.
Vulnerability Details
Multiple flaws were discovered in LibreOffice’s processing of crafted documents. An attacker could exploit these bugs to execute arbitrary code with the user’s privileges.
No active exploitation has been reported yet. The risk remains high for unpatched installations.
Critical warning: Do not open untrusted LibreOffice files until the update is applied.
Update Instructions
Run the package manager to fetch the security patch. Restart all LibreOffice instances after the update.
This advisory supersedes previous GSA notices for the same package. - Please update your systems.