• Welcome to Support Forum: Get Support for Patch My PC Products and Services.
 

No LibreOffice updates since version 6.1.1

Started by OldNavyGuy, February 05, 2019, 06:05:58 PM

Previous topic - Next topic

OldNavyGuy

Read an article today that a vulnerability had been patched in 6.1.3 but PatchMyPC does not detect any updates to 6.1.1.

https://www.bleepingcomputer.com/news/security/openoffice-vulnerable-to-remote-code-execution-libreoffice-patched/

Omar (Patch My PC)

Hey there,
We are using the latest "Still Branch" version of LibreOffice (6.0.7) which is already patched for these vulnerabilities months ago, and it's mentioned actually in the URL you sent :)

Here is the difference between Fresh Branch & Still Branch:
https://www.libreoffice.org/download/release-notes/

OldNavyGuy

Correct.

However, I am using the 6.1 branch, and there were issues with that.

From the article...

In the 6.1 series, the problem was compounded by an additional feature which enables specifying in the document arguments to pass to the python method (Earlier series only allow a method to be called with no argument). The bundled python happens to include a method which executes via os.system one of its arguments, providing a simple route in 6.1 to execute arbitrary commands via such a crafted document.

I was expecting 6.1.3 to show up as a result.

Omar (Patch My PC)

Unfortunately we can't use both Fresh Branch & Still Branch in Patch My PC right now, and many users were upset that we were using the Fresh Branch because they wanted the more secure and stable one "Still Branch".
But fortunately there is a new update for both today! Still Branch now is v6.1.5