PT-2019-3158 · Document Foundation+5 · Libreoffice+6

Alex

·

Published

2019-08-06

·

Updated

2024-06-15

·

CVE-2019-9850

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Document Foundation LibreOffice versions prior to 6.2.6
Description The issue is caused by insufficient URL validation in LibreOffice, which allows malicious actors to bypass protection and execute arbitrary python commands contained within a document. This can be triggered through script event handlers, such as mouse-over events, and can lead to the execution of arbitrary code in the target system. The vulnerability is related to the LibreLogo programmable turtle vector graphics script, which is typically bundled with LibreOffice.
Recommendations For versions prior to 6.2.6, update to version 6.2.6 or later to resolve the issue. As a temporary workaround, consider disabling the execution of pre-installed scripts from document script events to minimize the risk of exploitation. Restrict access to the LibreLogo script to prevent malicious actors from executing arbitrary code. Avoid opening documents from untrusted sources, as they may contain specially crafted files that can exploit this vulnerability.

Exploit

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2019-2380
ALT-PU-2019-2402
ALT-PU-2019-2490
ALT-PU-2019-2500
ALT-PU-2019-2760
ALT-PU-2019-2761
BDU:2019-03147
CESA-2020_1151
CESA-2020_1598
CVE-2019-9850
DLA-1947-1
DSA-4501-1
MGASA-2019-0340
OPENSUSE-SU-2019:2057-1
OPENSUSE-SU-2019:2183-1
OPENSUSE-SU-2019_2057-1
OPENSUSE-SU-2019_2183-1
OPENSUSE-SU-2024:10983-1
RHSA-2020:1151
RHSA-2020:1598
RHSA-2020_1151
RHSA-2020_1598
SUSE-SU-2019:2231-1
SUSE-SU-2019:2401-1
SUSE-SU-2019:2402-1
USN-4102-1

Affected Products

Alt Linux
Centos
Librelogo
Libreoffice
Red Hat
Suse
Ubuntu