REDHAT-BUG-2210186: Medium severity libreoffice draw vulnerability

Published May 26, 2023
·
Updated

Improper Validation of Array Index vulnerability in the spreadsheet component of The Document Foundation LibreOffice allows an attacker to craft a spreadsheet document that will cause an array index underflow when loaded. In the affected versions of LibreOffice certain malformed spreadsheet formulas, such as AGGREGATE, could be created with less parameters passed to the formula interpreter than it expected, leading to an array index underflow, in which case there is a risk that arbitrary code could be executed. This issue affects: The Document Foundation LibreOffice 7.4 versions prior to 7.4.6; 7.5 versions prior to 7.5.1.

https://www.libreoffice.org/about-us/security/advisories/CVE-2023-0950

Affected Software

1 affected component
The Document Foundation LibreOffice<7.4.6, <7.5.1

Event History

May 26, 2023
Data Sourced
via Red Hat·04:24 AM
DescriptionSeverityAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of REDHAT-BUG-2210186?

The severity of REDHAT-BUG-2210186 is classified as moderate considering the potential for an array index underflow.

2

How do I fix REDHAT-BUG-2210186?

To fix REDHAT-BUG-2210186, update LibreOffice to version 7.4.7 or later.

3

What versions of LibreOffice are affected by REDHAT-BUG-2210186?

Versions of LibreOffice up to and including 7.4.6 and 7.5.1 are affected by REDHAT-BUG-2210186.

4

What kind of vulnerability is REDHAT-BUG-2210186?

REDHAT-BUG-2210186 is identified as an Improper Validation of Array Index vulnerability.

5

What could happen if REDHAT-BUG-2210186 is exploited?

If exploited, REDHAT-BUG-2210186 could lead to potential crashes or unintended behavior in LibreOffice when processing malicious spreadsheet documents.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203