PT-2019-3257 · Microsoft+3 · Windows+3

Alex

·

Published

2019-09-06

·

Updated

2024-06-15

·

CVE-2019-9855

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Document Foundation LibreOffice versions prior to 6.2.7 Document Foundation LibreOffice versions prior to 6.3.1
Description The issue is related to LibreLogo, a programmable turtle vector graphics script bundled with LibreOffice, which can execute arbitrary python commands. A Windows 8.3 path equivalence handling flaw in LibreOffice under Windows allows a document to trigger executing LibreLogo via a Windows filename pseudonym, potentially enabling a remote attacker to execute arbitrary code in the target system using a specially crafted file.
Recommendations For versions prior to 6.2.7, update to version 6.2.7 or later. For versions prior to 6.3.1, update to version 6.3.1 or later.

Fix

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2019-2760
ALT-PU-2019-2761
BDU:2019-03247
CVE-2019-9855
OPENSUSE-SU-2019:2183-1
OPENSUSE-SU-2019:2361-1
OPENSUSE-SU-2019_2183-1
OPENSUSE-SU-2019_2361-1
OPENSUSE-SU-2024:10983-1
SUSE-SU-2019:2401-1
SUSE-SU-2019:2402-1
SUSE-SU-2019:2686-1

Affected Products

Alt Linux
Libreoffice
Suse
Windows