The Document Foundation publishes details of LibreOffice 3.4.3 security fixes

The Internet, October 4, 2011 – The Document Foundation (TDF) publishes some details of the security fixes included with the recently released LibreOffice 3.4.3, and included in the older 3.3.4 version. Following industry best practice, details of security fixes are withheld until users have been given time to migrate to the new version. RedHat security researcher Huzaifa Sidhpurwala identified a memory corruption vulnerability in the code responsible for loading Microsoft Word documents in LibreOffice. This flaw could have been used for nefarious purposes, such as installing viruses, through a specially-crafted file. The corresponding vulnerability description is CVE-2011-2713,”Out-of-bounds property read in binary .doc filter”. LibreOffice 3.4.3 also includes various improvements to the loading of Windows Metafile (.wmf) and Windows Enhanced Metafile (.emf) image formats that were found through fuzz testing. LibreOffice developers have developed some additional security patches and fixes. These are part of a general set of development improvements which are reflected in the overall quality and stability of the software. Most LibreOffice 3.4.3 security fixes have been developed by Caolan McNamara of RedHat and Marc-André Laverdière of Tata Consultancy Services. “Working on fuzzing LibreOffice import filters has been a great experience, and I am glad I could contribute in

LibreOffice Conference 2026 Call for Papers

Join us in Pordenone, Italy, to share what you are doing for and with LibreOffice, how you are integrating LibreOffice in your infrastructure, how you are using LibreOffice to achieve Digital Sovereignty, and how LibreOffice can be used in Education. The Document Foundation invites TDF Members, contributors and the wider FOSS community to submit talks, lectures and workshops for this year’s LibreOffice Conference that will be held in Pordenone, Italy. The event will take place from the 10th to the 12th of September, with an informal community meeting on September 9, and collateral events (in Italian) targeted to Italian enterprises and public administrations on September 9 and September 11. Proposals should be filed by June 15, 2026 in order to guarantee that they will be considered for inclusion in the conference program. Please provide an abstract of your talk, and a short bio of yourself. These will help organizers in selecting the talks, and putting together the conference schedule. The conference program will be based on the following tracks: a) Development (APIs, Extensions, Current and New Features) b) Quality Assurance and Software Security c) Localization, Documentation and Native Language Projects d) Appealing LibreOffice: Ease of Use, Design and Accessibility e)

LibreOffice for Education: Regaining Digital Sovereignty

Every year, millions of students open a laptop and log into Microsoft 365 or Google Workspace, surrendering their digital sovereignty to US Big Tech in the process. Teachers use cloud-based editors to assign homework. School administrators manage documents in proprietary formats. This ecosystem runs smoothly and seemingly without friction, but almost no one questions the cost of this normalisation. Unfortunately, the cost is quite high. An invisible resume Schools don’t just teach maths and history; they also teach mental processes, such as how to do research, think critically and interact with tools and institutions. Software is part of this invisible curriculum. A student who has spent years using Microsoft Word or Google Docs as the archetype of “word processing” or “collaboration” respectively has not developed neutral, transferable skills, but has become a future customer. This is not a conspiracy, but rather the way markets work. Microsoft and Google both offer heavily discounted or even free licences to educational institutions, knowing that brand loyalty formed in childhood tends to persist into adulthood and the working world. The licence discount is, in commercial terms, the cost of acquiring a new customer, which schools effectively pay on behalf of the seller. LibreOffice offers

LibreOffice 25.8.5 has arrived

Berlin, 19 February 2026 – LibreOffice 25.8.5, the fifth update to the FOSS office suite [1] developed by volunteers for personal productivity in office environments on Windows, MacOS and Linux, has landed at www.libreoffice.org/download. LibreOffice 25.8.5 is based on the highly robust LibreOffice technology platform, which supports the development of desktop, mobile, and cloud applications from both TDF and ecosystem companies. The platform supports all available document formats for full interoperability: the native, open and standard ODF (ODT, ODS and ODP) and the proprietary Microsoft OOXML (DOCX, XLSX and PPTX). Products based on LibreOffice Technology are available for all desktop operating systems (Windows, macOS, Linux and Chrome OS), mobile platforms (Android and iOS), and the cloud. For enterprise-class deployments, versions are available from ecosystem companies, with SLAs and security patch backports for three to five years. English manuals for the LibreOffice 25.8 family can be downloaded from books.libreoffice.org/en/. End users can access volunteer based technical support via mailing lists and the Ask LibreOffice forum: ask.libreoffice.org/. All desktop versions of LibreOffice can be downloaded from the same website: www.libreoffice.org/download/. To improve interoperability with Microsoft Office and 365, users should install the Microsoft Aptos font from this webpage: typography/font-list/aptos. LibreOffice enterprise and

Why open standards are extremely beneficial to end users

Whenever I talk to other technology users — including CTOs, CSOs and ICT managers, who in theory should have a certain level of expertise — I realise that most of them never consider standards when using applications, devices or websites. Users just want everything to work, but they don’t realise the fundamental role that standards, especially open standards, play in making this happen. Open standards actually offer users a significant advantage over the proprietary solutions they use every day. An open standard is a publicly available set of rules that govern how technology works. Anyone can use, develop or improve them. Examples include HTML for websites, USB for devices and PDF for documents. (And of course, the Open Document Format – ODF – as used by LibreOffice.) These are not owned by any company, and therefore benefit end users. That’s why they’re important to you. 1. You are not tied in Open standards reduce vendor lock-in. This means that users are not forced to use a single product or ecosystem from a single company to have control over their data and tools. For example, documents saved in an open format can be managed with multiple applications. If you change your

Announcement of LibreOffice 25.8.4

Berlin, 18 December 2025 – LibreOffice 25.8.4, the fourth minor update to the free office suite developed by volunteers for personal productivity in office environments on Windows, MacOS and Linux, is now available from the download page. With LibreOffice 25.2 reaching the end of life on 30 November, and the announcement of LibreOffice 26.2 scheduled for early February, this release is ready for production environments. It provides over 70 fixes which further improve the suite’s performance, reliability and interoperability. All LibreOffice users are encouraged to update their installations as soon as possible. LibreOffice 25.8.4 is based on the highly robust LibreOffice technology platform, which supports the development of desktop, mobile, and cloud applications from both TDF and ecosystem companies. The platform supports both available document formats for full interoperability: the native, open standard ODF (Open Document Format, ODT, ODS and ODP) and the proprietary Microsoft OOXML (DOCX, XLSX and PPTX). Products based on LibreOffice Technology are available for all desktop operating systems (Windows, macOS, Linux and Chrome OS), mobile platforms (Android and iOS), and the cloud. For enterprise-class deployments, versions are available from ecosystem companies with added features and benefits, such as SLAs and security patch backports for three to