Description
LibreOffice has a feature where documents can specify that pre-installed scripts can be executed on various document events such as mouse-over, etc. LibreOffice is typically also bundled with LibreLogo, a programmable turtle vector graphics script, which can be manipulated into executing arbitrary python commands. By using the document event feature to trigger LibreLogo to execute python contained within a document a malicious document could be constructed which would execute arbitrary python commands silently without warning. In the fixed versions, LibreLogo cannot be called from a document event handler. This issue affects: Document Foundation LibreOffice versions prior to 6.2.5.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-1947-1 | libreoffice security update |
Debian DSA |
DSA-4483-1 | libreoffice security update |
Debian DSA |
DSA-4501-1 | libreoffice security update |
Ubuntu USN |
USN-4063-1 | LibreOffice vulnerabilities |
References
History
No history.
Status: PUBLISHED
Assigner: Document Fdn.
Published:
Updated: 2024-09-16T22:50:55.703Z
Reserved: 2019-03-17T00:00:00.000Z
Link: CVE-2019-9848
No data.
Status : Modified
Published: 2019-07-17T12:15:10.770
Modified: 2024-11-21T04:52:25.910
Link: CVE-2019-9848
OpenCVE Enrichment
No data.
Debian DLA
Debian DSA
Ubuntu USN