← Back

CVE-2019-9854

nvd nist
Published: Sep 6, 2019Modified: Nov 21, 2024

JSON object

Loading...
7.8
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: NVD

Description

LibreOffice has a feature where documents can specify that pre-installed macros can be executed on various script events such as mouse-over, document-open etc. Access is intended to be restricted to scripts under the share/Scripts/python, user/Scripts/python sub-directories of the LibreOffice install. Protection was added, to address CVE-2019-9852, to avoid a directory traversal attack where scripts in arbitrary locations on the file system could be executed by employing a URL encoding attack to defeat the path verification step. However this protection could be bypassed by taking advantage of a flaw in how LibreOffice assembled the final script URL location directly from components of the passed in path as opposed to solely from the sanitized output of the path verification step. This issue affects: Document Foundation LibreOffice 6.2 versions prior to 6.2.7; 6.3 versions prior to 6.3.1.

Affected (13)

Show all products
1 product
Libreoffice
1 product
Ubuntu Linux
1 product
Debian Linux
1 product
Fedora
1 product
Leap
1 product
Enterprise Linux
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
Libreoffice
From 6.2.0 to 6.2.7
From 6.3.0 to 6.3.1
Configuration B
11 vulnerable
Vulnerable SoftwareAffected Versions
Canonical
Version 16.04
Version 18.04
Version 19.04
Debian
Version 10.0
Version 8.0
Version 9.0
Version 29
Opensuse
Version 15.0
Version 15.1
Redhat
Version 7.0
Version 8.0

References (17)

Source: security@documentfoundation.org
Third Party Advisory
Source: security@documentfoundation.org
Third Party Advisory
Source: security@documentfoundation.org
Third Party Advisory
Source: security@documentfoundation.org
Mailing ListThird Party Advisory
Source: security@documentfoundation.org
Third Party Advisory
Source: security@documentfoundation.org
Third Party Advisory
Source: security@documentfoundation.org
Vendor Advisory
Source: nvd@nist.gov
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.