First published: Wed Jul 17 2019(Updated: )
Last updated 24 July 2024
Credit: security@documentfoundation.org
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/libreoffice | <6.2.5 | 6.2.5 |
debian/libreoffice | 1:7.0.4-4+deb11u10 4:7.4.7-1+deb12u4 4:7.4.7-1+deb12u5 4:24.2.5-4 4:24.2.6-1 | |
LibreOffice Draw | <6.2.5 | |
Ubuntu | =16.04 | |
Ubuntu | =18.04 | |
Ubuntu | =19.04 | |
Fedora | =29 | |
Fedora | =30 | |
Debian | =8.0 | |
SUSE Linux | =15.0 | |
SUSE Linux | =15.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-9848 is a vulnerability in LibreOffice that allows pre-installed scripts to be executed on various document events.
The severity of CVE-2019-9848 is critical, with a severity value of 9.8.
The affected software versions include LibreOffice 6.0.7 on Ubuntu 18.04, LibreOffice 6.2.5 on Ubuntu 19.04, and LibreOffice 5.1.6~ on Ubuntu 16.04.
To fix CVE-2019-9848, it is recommended to update LibreOffice to the latest version available.
Yes, you can find references for CVE-2019-9848 at the following links: http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00006.html, http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00067.html, http://www.securityfocus.com/bid/109374.