As per upstream libreoffice advisory: In LibreOffice 4.0.0 and later, a new feature was added for remote control capabilities in Impress. Users can run a smart phone application to communicate with Impress over a custom protocol to switch slides and the like. By default whenever Impress is started, it immediately began listening on TCP port 1599 on all interfaces. But there was a use after free bug in the code managing that port leaving LibreOffice vulnerable to external attackers with access to that port where those external attackers could cause the deleted port manager to continue to process attacker supplied data. All users are recommended to upgrade to LibreOffice 4.2.7 or 4.3.3. The impress remote can be disabled by: 1. Open LibreOffice, go to "Tools -> Options..." 2. Select "LibreOffice Impress -> General" 3. Uncheck "Presentation -> Enable remote control" External References: http://www.libreoffice.org/about-us/security/advisories/cve-2014-3693
Created libreoffice tracking bugs for this issue: Affects: fedora-all [bug 1167503]
Statement: This issue affects the versions of libreoffice as shipped with Red Hat Enterprise Linux 6. Red Hat Product Security has rated this issue as having Moderate security impact. A future update may address this issue.
Upstream patch: http://cgit.freedesktop.org/libreoffice/core/commit/?h=libreoffice-4-3&id=3d0cffab8d06a0f8af6c0ed7a95728203080a7c5
This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Via RHSA-2015:0377 https://rhn.redhat.com/errata/RHSA-2015-0377.html