LibreOffice has a feature where documents can specify that pre-installed macros can be executed on various script events such as mouse-over, document-open etc. Access is intended to be restricted to scripts under the share/Scripts/python, user/Scripts/python sub-directories of the LibreOffice install. Protection was added, to address CVE-2018-16858, to avoid a directory traversal attack where scripts in arbitrary locations on the file system could be executed. However this new protection could be bypassed by a URL encoding attack. In the fixed versions, the parsed url describing the script location is correctly encoded before further processing. This issue affects: Document Foundation LibreOffice versions prior to 6.2.6.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-1947-1 | libreoffice security update |
Debian DSA |
DSA-4501-1 | libreoffice security update |
Debian DSA |
DSA-4519-1 | libreoffice security update |
EUVD |
EUVD-2019-19208 | LibreOffice has a feature where documents can specify that pre-installed macros can be executed on various script events such as mouse-over, document-open etc. Access is intended to be restricted to scripts under the share/Scripts/python, user/Scripts/python sub-directories of the LibreOffice install. Protection was added, to address CVE-2018-16858, to avoid a directory traversal attack where scripts in arbitrary locations on the file system could be executed. However this new protection could be bypassed by a URL encoding attack. In the fixed versions, the parsed url describing the script location is correctly encoded before further processing. This issue affects: Document Foundation LibreOffice versions prior to 6.2.6. |
Ubuntu USN |
USN-4102-1 | LibreOffice vulnerabilities |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Status: PUBLISHED
Assigner: Document Fdn.
Published:
Updated: 2024-09-17T03:42:47.414Z
Reserved: 2019-03-17T00:00:00
Link: CVE-2019-9852
No data.
Status : Modified
Published: 2019-08-15T22:15:22.350
Modified: 2024-11-21T04:52:26.423
Link: CVE-2019-9852
OpenCVE Enrichment
No data.
Debian DLA
Debian DSA
EUVD
Ubuntu USN