PT-2019-3257 · Microsoft+3 · Windows+3
Alex
·
Publicado
2019-09-06
·
Atualizado
2024-06-15
·
CVE-2019-9855
CVSS v2.0
10
Crítica
| Vetor | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Document Foundation LibreOffice versions prior to 6.2.7
Document Foundation LibreOffice versions prior to 6.3.1
Description
The issue is related to LibreLogo, a programmable turtle vector graphics script bundled with LibreOffice, which can execute arbitrary python commands. A Windows 8.3 path equivalence handling flaw in LibreOffice under Windows allows a document to trigger executing LibreLogo via a Windows filename pseudonym, potentially enabling a remote attacker to execute arbitrary code in the target system using a specially crafted file.
Recommendations
For versions prior to 6.2.7, update to version 6.2.7 or later.
For versions prior to 6.3.1, update to version 6.3.1 or later.
Correção
Improper Privilege Management
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Alt Linux
Libreoffice
Suse
Windows