PT-2023-22107 · Document Foundation · Libreoffice
Published
2023-11-02
·
Updated
2024-01-12
·
CVE-2023-29043
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
LibreOffice versions prior to 7.4.5
Description
Presentations may contain references to images, which are user-controlled, and could include malicious script code that is being processed when editing a document. Script code embedded in malicious documents could be executed in the context of the user editing the document when performing certain actions, like copying content. The relevant attribute does now get encoded to avoid the possibility of executing script code. No publicly available exploits are known.
Recommendations
For versions prior to 7.4.5, update to version 7.4.5 or later to resolve the issue. As a temporary workaround, consider avoiding the use of user-controlled images in presentations until a patch is available. Restrict access to potentially malicious documents to minimize the risk of exploitation.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Libreoffice