PT-2017-2764 · Apache+4 · Apache Openoffice+5

Ben Hayak

·

Published

2017-02-22

·

Updated

2024-06-15

·

CVE-2017-3157

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions LibreOffice (affected versions not specified) Apache OpenOffice versions prior to 4.1.4
Description The issue is related to the improper handling of opened files, allowing an attacker to disclose protected information using a specially crafted file. Exploitation of this issue in Apache OpenOffice can enable an attacker to read files from the user's filesystem by crafting a document with embedded objects. The attacker could retrieve information by tricking the user into saving the document and sending it back. This is mitigated by the attacker needing to know the precise file path and tricking the user into saving and sending the document.
Recommendations For Apache OpenOffice versions prior to 4.1.4, update to version 4.1.4 or later to resolve the issue. At the moment, there is no information about a newer version that contains a fix for this vulnerability in LibreOffice.

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2017-02018
CESA-2017_0914
CESA-2017_0979
CVE-2017-3157
DLA-910-1
DSA-3792-1
OPENSUSE-SU-2024:10983-1
RHSA-2017:0914
RHSA-2017:0979
RHSA-2017_0914
RHSA-2017_0979
USN-3210-1

Affected Products

Apache Openoffice
Centos
Libreoffice
Openoffice
Red Hat
Ubuntu