First published: Thu Aug 15 2019(Updated: )
A vulnerability was found in LibreOffice prior to 6.2.6. LibreOffice has a feature where documents can specify that pre-installed macros can be executed on various script events such as mouse-over, document-open etc. Access is intended to be restricted to scripts under the share/Scripts/python, user/Scripts/python sub-directories of the LibreOffice install. Protection was added, to address <a href="https://access.redhat.com/security/cve/CVE-2018-16858">CVE-2018-16858</a>, to avoid a directory traversal attack where scripts in arbitrary locations on the file system could be executed. However this new protection could be bypassed by a URL encoding attack. In the fixed versions, the parsed url describing the script location is correctly encoded before further processing. Reference: <a href="https://seclists.org/bugtraq/2019/Aug/28">https://seclists.org/bugtraq/2019/Aug/28</a>
Credit: security@documentfoundation.org security@documentfoundation.org
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/LibreOffice | <6.2.6 | 6.2.6 |
redhat/LibreOffice | <6.3.0 | 6.3.0 |
debian/libreoffice | 1:7.0.4-4+deb11u10 1:7.0.4-4+deb11u11 4:7.4.7-1+deb12u4 4:7.4.7-1+deb12u5 4:24.8.2-1 4:24.8.2-2 | |
Ubuntu Linux | =16.04 | |
Ubuntu Linux | =18.04 | |
Ubuntu Linux | =19.04 | |
Debian Debian Linux | =8.0 | |
Debian Debian Linux | =9.0 | |
Debian Debian Linux | =10.0 | |
Fedoraproject Fedora | =29 | |
openSUSE | =15.0 | |
openSUSE | =15.1 | |
The Document Foundation LibreOffice | <6.2.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-9852 is a vulnerability in LibreOffice that allows documents to execute pre-installed macros on various script events, which can lead to unauthorized execution of potentially malicious code.
CVE-2019-9852 has a severity rating of 7.8, which is considered high.
LibreOffice versions 6.0.7-0ubuntu0.18.04.9, 6.2.6-0ubuntu0.19.04.1, 6.3.0-1, 5.1.6~, 6.2.6, and 6.3.0 are affected by CVE-2019-9852.
To fix CVE-2019-9852, update LibreOffice to versions 6.0.7-0ubuntu0.18.04.9, 6.2.6-0ubuntu0.19.04.1, 6.3.0-1, 5.1.6~, 6.2.6, or 6.3.0 or apply the necessary patches provided by your operating system or software vendor.
You can find more information about CVE-2019-9852 at the following references: [link1], [link2], [link3].