LibreOffice supports Office URI Schemes to enable browser integration of LibreOffice with MS SharePoint server. An additional scheme 'vnd.libreoffice.command' specific to LibreOffice was added. In the affected versions of LibreOffice links using that scheme could be constructed to call internal macros with arbitrary arguments. Which when clicked on, or activated by document events, could result in arbitrary script execution without warning. This issue affects: The Document Foundation LibreOffice 7.4 versions prior to 7.4.1; 7.3 versions prior to 7.3.6.
Advisories
Source ID Title
Debian DLA Debian DLA DLA-3368-1 libreoffice security update
Debian DSA Debian DSA DSA-5252-1 libreoffice security update
EUVD EUVD EUVD-2022-42567 LibreOffice supports Office URI Schemes to enable browser integration of LibreOffice with MS SharePoint server. An additional scheme 'vnd.libreoffice.command' specific to LibreOffice was added. In the affected versions of LibreOffice links using that scheme could be constructed to call internal macros with arbitrary arguments. Which when clicked on, or activated by document events, could result in arbitrary script execution without warning. This issue affects: The Document Foundation LibreOffice 7.4 versions prior to 7.4.1; 7.3 versions prior to 7.3.6.
Ubuntu USN Ubuntu USN USN-5694-1 LibreOffice vulnerabilities
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: Document Fdn.

Published:

Updated: 2024-08-03T01:00:10.521Z

Reserved: 2022-09-06T00:00:00

Link: CVE-2022-3140

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2022-10-11T21:15:16.367

Modified: 2024-11-21T07:18:54.577

Link: CVE-2022-3140

cve-icon Redhat

Severity : Moderate

Publid Date: 2022-10-11T00:00:00Z

Links: CVE-2022-3140 - Bugzilla

cve-icon OpenCVE Enrichment

No data.