PT-2019-2804 · Document Foundation+5 · Libreoffice+5

Nils Emmerich

·

Publicado

2019-07-16

·

Atualizado

2024-06-15

·

CVE-2019-9848

CVSS v3.1

10

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Document Foundation LibreOffice versions prior to 6.2.5
Description The issue allows a malicious document to execute arbitrary python commands silently without warning by using the document event feature to trigger LibreLogo to execute python contained within a document. This is possible due to the presence of mechanisms in the LibreLogo module that launch software algorithms in the Python language when a malicious object is hovered over. Exploitation of this issue may allow a remote attacker to execute arbitrary code on the target system by sending a specially crafted document in formats such as .doc, .docx, .xls, .xlsx, .ppt, .pptx.
Recommendations For versions prior to 6.2.5, update to version 6.2.5 or later, where LibreLogo cannot be called from a document event handler, to resolve the issue. As a temporary workaround, consider disabling the use of LibreLogo in document event handlers until a patch is available. Restrict access to documents from untrusted sources to minimize the risk of exploitation.

Exploit

Correção

RCE

Code Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2019-2380
ALT-PU-2019-2402
ALT-PU-2019-2490
ALT-PU-2019-2500
BDU:2019-02759
CESA-2020_1151
CVE-2019-9848
DLA-1947-1
DSA-4483-1
DSA-4501-1
MGASA-2019-0340
OPENSUSE-SU-2019:2057-1
OPENSUSE-SU-2019:2183-1
OPENSUSE-SU-2019_2057-1
OPENSUSE-SU-2019_2183-1
OPENSUSE-SU-2024:10983-1
RHSA-2020:1151
RHSA-2020_1151
SUSE-SU-2019:2231-1
SUSE-SU-2019:2401-1
SUSE-SU-2019:2402-1
SUSE-SU-2019_2401-1
SUSE-SU-2019_2402-1
USN-4063-1

Produtos afetados

Alt Linux
Centos
Libreoffice
Red Hat
Suse
Ubuntu