PT-2019-3158 · Document Foundation+5 · Libreoffice+6
Alex
·
Published
2019-08-06
·
Updated
2024-06-15
·
CVE-2019-9850
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Document Foundation LibreOffice versions prior to 6.2.6
Description
The issue is caused by insufficient URL validation in LibreOffice, which allows malicious actors to bypass protection and execute arbitrary python commands contained within a document. This can be triggered through script event handlers, such as mouse-over events, and can lead to the execution of arbitrary code in the target system. The vulnerability is related to the LibreLogo programmable turtle vector graphics script, which is typically bundled with LibreOffice.
Recommendations
For versions prior to 6.2.6, update to version 6.2.6 or later to resolve the issue. As a temporary workaround, consider disabling the execution of pre-installed scripts from document script events to minimize the risk of exploitation. Restrict access to the LibreLogo script to prevent malicious actors from executing arbitrary code. Avoid opening documents from untrusted sources, as they may contain specially crafted files that can exploit this vulnerability.
Exploit
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Centos
Librelogo
Libreoffice
Red Hat
Suse
Ubuntu