CVE-2019-9848: Code Injection
Last updated 25 August 2025
Other sources
LibreLogo, a programmable turtle vector graphics script, which can be manipulated into executing arbitrary python commands. By using the document event feature to trigger LibreLogo to execute python contained within a document a malicious document could be constructed which would execute arbitrary python commands silently without warning. This issue affects: Document Foundation LibreOffice versions prior to 6.2.5.
External References:
https://www.libreoffice.org/about-us/security/advisories/CVE-2019-9848
— Red Hat
LibreOffice has a feature where documents can specify that pre-installed scripts can be executed on various document events such as mouse-over, etc. LibreOffice is typically also bundled with LibreLogo, a programmable turtle vector graphics script, which can be manipulated into executing arbitrary python commands. By using the document event feature to trigger LibreLogo to execute python contained within a document a malicious document could be constructed which would execute arbitrary python commands silently without warning. In the fixed versions, LibreLogo cannot be called from a document event handler. This issue affects: Document Foundation LibreOffice versions prior to 6.2.5.
— Launchpad
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-9848?
CVE-2019-9848 is a vulnerability in LibreOffice that allows pre-installed scripts to be executed on various document events.
What is the severity of CVE-2019-9848?
The severity of CVE-2019-9848 is critical, with a severity value of 9.8.
Which software versions are affected by CVE-2019-9848?
The affected software versions include LibreOffice 6.0.7 on Ubuntu 18.04, LibreOffice 6.2.5 on Ubuntu 19.04, and LibreOffice 5.1.6~ on Ubuntu 16.04.
How can I fix CVE-2019-9848?
To fix CVE-2019-9848, it is recommended to update LibreOffice to the latest version available.
Are there any references for CVE-2019-9848?
Yes, you can find references for CVE-2019-9848 at the following links: http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00006.html, http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00067.html, http://www.securityfocus.com/bid/109374.