PT-2019-2949 · Document Foundation+5 · Libreoffice+5

Matei

·

Published

2019-07-16

·

Updated

2022-04-18

·

CVE-2019-9849

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions LibreOffice versions prior to 6.2.5
Description The issue is related to the 'stealth mode' in LibreOffice, which is intended to restrict remote resource retrieval to only trusted locations. However, a flaw existed where bullet graphics were not protected, potentially allowing unauthorized access to sensitive information, execution of arbitrary code, or denial of service by a remote attacker.
Recommendations For versions prior to 6.2.5, update to version 6.2.5 or later to resolve the issue. As a temporary workaround, consider disabling the use of remote resources within documents until the update is applied.

Exploit

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2019-2380
ALT-PU-2019-2402
ALT-PU-2019-2490
ALT-PU-2019-2500
ALT-PU-2019-2760
ALT-PU-2019-2761
BDU:2019-02924
CESA-2020_1151
CESA-2020_1598
CVE-2019-9849
DLA-1947-1
DSA-4483-1
MGASA-2019-0340
OPENSUSE-SU-2019:2057-1
OPENSUSE-SU-2019:2183-1
OPENSUSE-SU-2019_2057-1
OPENSUSE-SU-2019_2183-1
RHSA-2020:1151
RHSA-2020:1598
RHSA-2020_1151
RHSA-2020_1598
SUSE-SU-2019:2231-1
SUSE-SU-2019:2401-1
SUSE-SU-2019:2402-1
USN-4063-1

Affected Products

Alt Linux
Centos
Libreoffice
Red Hat
Suse
Ubuntu