PT-2019-5536 · Document Foundation+5 · Libreoffice+5

Nils Emmerich

·

Published

2019-08-15

·

Updated

2024-06-15

·

CVE-2019-9853

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions LibreOffice versions 6.2.0 through 6.2.6 LibreOffice versions 6.3.0 through 6.3.0
Description A URL decoding flaw existed in how the URLs to the macros within the document were processed and categorized, resulting in the possibility to construct a document where macro execution bypassed the security settings. The documents were correctly detected as containing macros, and prompted the user to their existence within the documents, but macros within the document were subsequently not controlled by the security settings allowing arbitrary macro execution. This issue may allow a remote attacker to gain unauthorized access to confidential data, cause a denial of service, or impact data integrity.
Recommendations For LibreOffice 6.2 series versions prior to 6.2.7, update to version 6.2.7 or later. For LibreOffice 6.3 series versions prior to 6.3.1, update to version 6.3.1 or later. As a temporary workaround, consider disabling macro execution in the document security settings until a patch is available. Restrict access to documents containing macros to minimize the risk of exploitation.

Exploit

Fix

Improper Encoding or Escaping of Output

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2020-2699
ALT-PU-2020-3097
BDU:2020-03850
CESA-2020_1151
CESA-2020_1598
CVE-2019-9853
DLA-1947-1
DSA-4501-1
MGASA-2019-0340
OPENSUSE-SU-2019:2709-1
OPENSUSE-SU-2019_2709-1
OPENSUSE-SU-2024:10983-1
RHSA-2020:1151
RHSA-2020:1598
RHSA-2020_1151
RHSA-2020_1598
SUSE-SU-2019_3313-1
SUSE-SU-2020:0121-1
SUSE-SU-2020:0372-1
SUSE-SU-2020_0121-1
SUSE-SU-2020_0372-1
USN-4102-1

Affected Products

Alt Linux
Centos
Libreoffice
Openoffice
Red Hat
Suse