PT-2019-3256 · Document Foundation+5 · Libreoffice+5
Ricex
·
Published
2019-09-06
·
Updated
2024-06-15
·
CVE-2019-9854
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
LibreOffice versions 6.2 prior to 6.2.7
LibreOffice versions 6.3 prior to 6.3.1
Description
The issue is related to how LibreOffice handles script events, such as mouse-over and document-open, where pre-installed macros can be executed. A flaw in the path verification step allows an attacker to bypass protection and execute scripts in arbitrary locations on the file system. This is done by exploiting a flaw in how LibreOffice assembles the final script URL location from components of the passed-in path, rather than solely from the sanitized output of the path verification step. The estimated number of potentially affected devices worldwide is not specified.
Recommendations
For LibreOffice versions 6.2 prior to 6.2.7, update to version 6.2.7 or later.
For LibreOffice versions 6.3 prior to 6.3.1, update to version 6.3.1 or later.
As a temporary workaround, consider restricting access to scripts under the share/Scripts/python and user/Scripts/python sub-directories of the LibreOffice install to minimize the risk of exploitation.
Exploit
Fix
Improper Access Control
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Centos
Libreoffice
Red Hat
Suse
Ubuntu