PT-2019-3256 · Document Foundation+5 · Libreoffice+5

Ricex

·

Published

2019-09-06

·

Updated

2024-06-15

·

CVE-2019-9854

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions LibreOffice versions 6.2 prior to 6.2.7 LibreOffice versions 6.3 prior to 6.3.1
Description The issue is related to how LibreOffice handles script events, such as mouse-over and document-open, where pre-installed macros can be executed. A flaw in the path verification step allows an attacker to bypass protection and execute scripts in arbitrary locations on the file system. This is done by exploiting a flaw in how LibreOffice assembles the final script URL location from components of the passed-in path, rather than solely from the sanitized output of the path verification step. The estimated number of potentially affected devices worldwide is not specified.
Recommendations For LibreOffice versions 6.2 prior to 6.2.7, update to version 6.2.7 or later. For LibreOffice versions 6.3 prior to 6.3.1, update to version 6.3.1 or later. As a temporary workaround, consider restricting access to scripts under the share/Scripts/python and user/Scripts/python sub-directories of the LibreOffice install to minimize the risk of exploitation.

Exploit

Fix

Improper Access Control

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2019-2760
ALT-PU-2019-2761
ALT-PU-2020-2699
ALT-PU-2020-3097
BDU:2019-03246
CESA-2020_1151
CESA-2020_1598
CVE-2019-9854
DLA-1947-1
DSA-4519-1
MGASA-2019-0340
OPENSUSE-SU-2019:2183-1
OPENSUSE-SU-2019:2361-1
OPENSUSE-SU-2019_2183-1
OPENSUSE-SU-2019_2361-1
OPENSUSE-SU-2024:10983-1
RHSA-2020:1151
RHSA-2020:1598
RHSA-2020_1151
RHSA-2020_1598
SUSE-SU-2019:2401-1
SUSE-SU-2019:2402-1
SUSE-SU-2019:2686-1
USN-4138-1

Affected Products

Alt Linux
Centos
Libreoffice
Red Hat
Suse
Ubuntu