CVE-2019-9849: Medium severity libreoffice draw vulnerability
Last updated 24 July 2024
Other sources
LibreOffice has a 'stealth mode' in which only documents from locations deemed 'trusted' are allowed to retrieve remote resources. A flaw existed where bullet graphics were omitted from this protection prior to version 6.2.5.
External References:
https://www.libreoffice.org/about-us/security/advisories/CVE-2019-9849
— Red Hat
LibreOffice has a 'stealth mode' in which only documents from locations deemed 'trusted' are allowed to retrieve remote resources. This mode is not the default mode, but can be enabled by users who want to disable LibreOffice's ability to include remote resources within a document. A flaw existed where bullet graphics were omitted from this protection prior to version 6.2.5. This issue affects: Document Foundation LibreOffice versions prior to 6.2.5.
— Launchpad
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this security flaw?
The vulnerability ID for this security flaw is CVE-2019-9849.
What is the severity level of CVE-2019-9849?
CVE-2019-9849 has a severity level of medium with a CVSS score of 4.3.
How can I fix the CVE-2019-9849 vulnerability in LibreOffice?
To fix the CVE-2019-9849 vulnerability in LibreOffice, you should update to version 6.0.7-0ubuntu0.18.04.8 (for Ubuntu 18.04) or version 6.2.5-0ubuntu0.19.04.1 (for Ubuntu 19.04) or apply the appropriate remedy provided by your Linux distribution.
What is the default mode in LibreOffice that includes remote resources within a document?
The default mode in LibreOffice that includes remote resources within a document is not the 'stealth mode'.
Who discovered the CVE-2019-9849 vulnerability?
The CVE-2019-9849 vulnerability was discovered and reported by security researchers.