PT-2019-3257 · Microsoft+3 · Windows+3
Alex
·
Published
2019-09-06
·
Updated
2024-06-15
·
CVE-2019-9855
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Document Foundation LibreOffice versions prior to 6.2.7
Document Foundation LibreOffice versions prior to 6.3.1
Description
The issue is related to LibreLogo, a programmable turtle vector graphics script bundled with LibreOffice, which can execute arbitrary python commands. A Windows 8.3 path equivalence handling flaw in LibreOffice under Windows allows a document to trigger executing LibreLogo via a Windows filename pseudonym, potentially enabling a remote attacker to execute arbitrary code in the target system using a specially crafted file.
Recommendations
For versions prior to 6.2.7, update to version 6.2.7 or later.
For versions prior to 6.3.1, update to version 6.3.1 or later.
Fix
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Libreoffice
Suse
Windows