A flaw was found in the Libreoffice package. An attacker can craft an odb containing a "database/script" file with a SCRIPT command where the contents of the file could be written to a new file whose location was determined by the attacker.
Advisories
Source ID Title
Debian DLA Debian DLA DLA-3467-1 hsqldb security update
Debian DLA Debian DLA DLA-3468-1 hsqldb1.8.0 security update
Debian DSA Debian DSA DSA-5436-1 hsqldb1.8.0 security update
Debian DSA Debian DSA DSA-5437-1 hsqldb security update
Debian DSA Debian DSA DSA-5995-1 hsqldb1.8.0 security update
EUVD EUVD EUVD-2023-23463 A flaw was found in the Libreoffice package. An attacker can craft an odb containing a "database/script" file with a SCRIPT command where the contents of the file could be written to a new file whose location was determined by the attacker.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2025-02-13T16:39:16.576Z

Reserved: 2023-03-06T04:37:10.705Z

Link: CVE-2023-1183

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2023-07-10T16:15:48.773

Modified: 2024-11-21T07:38:37.307

Link: CVE-2023-1183

cve-icon Redhat

Severity : Moderate

Publid Date: 2023-06-19T00:00:00Z

Links: CVE-2023-1183 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses