PT-2019-3257 · Microsoft+3 · Windows+3

Alex

·

Publicado

2019-09-06

·

Atualizado

2024-06-15

·

CVE-2019-9855

CVSS v2.0

10

Crítica

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Document Foundation LibreOffice versions prior to 6.2.7 Document Foundation LibreOffice versions prior to 6.3.1
Description The issue is related to LibreLogo, a programmable turtle vector graphics script bundled with LibreOffice, which can execute arbitrary python commands. A Windows 8.3 path equivalence handling flaw in LibreOffice under Windows allows a document to trigger executing LibreLogo via a Windows filename pseudonym, potentially enabling a remote attacker to execute arbitrary code in the target system using a specially crafted file.
Recommendations For versions prior to 6.2.7, update to version 6.2.7 or later. For versions prior to 6.3.1, update to version 6.3.1 or later.

Correção

Improper Privilege Management

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2019-2760
ALT-PU-2019-2761
BDU:2019-03247
CVE-2019-9855
OPENSUSE-SU-2019:2183-1
OPENSUSE-SU-2019:2361-1
OPENSUSE-SU-2019_2183-1
OPENSUSE-SU-2019_2361-1
OPENSUSE-SU-2024:10983-1
SUSE-SU-2019:2401-1
SUSE-SU-2019:2402-1
SUSE-SU-2019:2686-1

Produtos afetados

Alt Linux
Libreoffice
Suse
Windows