Unchecked script execution in Graphic on-click binding in affected LibreOffice versions allows an attacker to create a document which without prompt will execute scripts built-into LibreOffice on clicking a graphic. Such scripts were previously deemed trusted but are now deemed untrusted.

Project Subscriptions

Vendors Products
Debian Linux Subscribe
Fedoraproject Subscribe
Libreoffice Subscribe
Libreoffice Subscribe
Enterprise Linux Subscribe
Advisories
Source ID Title
Debian DLA Debian DLA DLA-3821-1 libreoffice security update
Debian DSA Debian DSA DSA-5690-1 libreoffice security update
Ubuntu USN Ubuntu USN USN-6789-1 LibreOffice vulnerability
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 10 Dec 2025 19:15:00 +0000

Type Values Removed Values Added
First Time appeared Debian
Debian debian Linux
Fedoraproject
Fedoraproject fedora
Libreoffice
Libreoffice libreoffice
CPEs cpe:2.3:a:libreoffice:libreoffice:*:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:39:*:*:*:*:*:*:*
Vendors & Products Debian
Debian debian Linux
Fedoraproject
Fedoraproject fedora
Libreoffice
Libreoffice libreoffice

Tue, 12 Nov 2024 21:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-94
Metrics cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H'}

cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L'}


Fri, 20 Sep 2024 10:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 20 Sep 2024 10:15:00 +0000

Type Values Removed Values Added
Description Unchecked script execution in Graphic on-click binding in affected LibreOffice versions allows an attacker to create a document which without prompt will execute scripts built-into LibreOffice on clicking a graphic. Such scripts were previously deemed trusted but are now deemed untrusted. Unchecked script execution in Graphic on-click binding in affected LibreOffice versions allows an attacker to create a document which without prompt will execute scripts built-into LibreOffice on clicking a graphic. Such scripts were previously deemed trusted but are now deemed untrusted.
Weaknesses CWE-356

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: Document Fdn.

Published:

Updated: 2024-11-12T20:14:27.961Z

Reserved: 2024-03-28T15:28:21.866Z

Link: CVE-2024-3044

cve-icon Vulnrichment

Updated: 2024-08-01T19:32:42.580Z

cve-icon NVD

Status : Analyzed

Published: 2024-05-14T21:15:12.627

Modified: 2025-12-10T19:10:17.363

Link: CVE-2024-3044

cve-icon Redhat

Severity : Moderate

Publid Date: 2024-05-14T00:00:00Z

Links: CVE-2024-3044 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses