v9.4.0
ONLYOFFICE-DesktopEditors-9.4.0
Added 7
- Add Croatian language interface translation (hr-HR, Hrvatska)
- Add options for pasting from the clipboard for the Paste button on the top toolbar
- Implement the ability to add a horizontal line in Document Editor
- Add Dark mode support for the sheet in Spreadsheet Editor
- Add 25 new presentation design themes in Presentation Editor
- Add 20 new slide transitions grouped by category in Presentation Editor
- Add Send for signing and Filling status panels in Forms
Changed 2
- Move chart settings from the right panel to a separate Chart design tab
- Save the most recently added image in the Signature field so it can be automatically used when filling out the form again
Security 3
- Fix out-of-bounds read vulnerabilities when converting XLS to XLSX in ChartSheetSubstream::recalc, TextPropsStream::readFields, MetroBlob::ReadComplexData, SUPBOOK::serialize_book and ATTACHEDLABEL::serialize_rPr
- Fix a vulnerability in GUID generation that allowed an attacker to calculate GUIDs based on their creation time
- Fix a vulnerability that allowed bypassing macro sandbox restrictions and accessing environment objects via sloppy-mode this and eval
New features
All Editors
- Added Croatian language interface translation (hr-HR, Hrvatska)
- Moved chart settings from the right panel to a separate Chart design tab
- Added options for pasting from the clipboard for the Paste button on the top toolbar
Document Editor
- Implemented the ability to add a horizontal line
Spreadsheet Editor
- Added the Dark mode support for the sheet
Presentation Editor
- Added 25 new presentation design themes
- Added 20 new slide transitions, grouped by category
Forms
- The app saves the most recently added image in the Signature field so it can be automatically used when filling out the form again
- Added the "Send for signing" and "Filling status" panels
Security
- Fixed out-of-bounds read vulnerabilities when converting XLS to XLSX in the following
functions:
ChartSheetSubstream::recalc,TextPropsStream::readFields,MetroBlob::ReadComplexData,SUPBOOK::serialize_bookandATTACHEDLABEL::serialize_rPr - Fixed a vulnerability in GUID generation that allowed an attacker to calculate GUIDs based on their creation time
- Fixed a vulnerability that allowed bypassing macro sandbox restrictions and accessing
environment objects via sloppy-mode
thisandeval