REDHAT-BUG-2210186: Medium severity libreoffice draw vulnerability
Improper Validation of Array Index vulnerability in the spreadsheet component of The Document Foundation LibreOffice allows an attacker to craft a spreadsheet document that will cause an array index underflow when loaded. In the affected versions of LibreOffice certain malformed spreadsheet formulas, such as AGGREGATE, could be created with less parameters passed to the formula interpreter than it expected, leading to an array index underflow, in which case there is a risk that arbitrary code could be executed. This issue affects: The Document Foundation LibreOffice 7.4 versions prior to 7.4.6; 7.5 versions prior to 7.5.1.
https://www.libreoffice.org/about-us/security/advisories/CVE-2023-0950
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2210186?
The severity of REDHAT-BUG-2210186 is classified as moderate considering the potential for an array index underflow.
How do I fix REDHAT-BUG-2210186?
To fix REDHAT-BUG-2210186, update LibreOffice to version 7.4.7 or later.
What versions of LibreOffice are affected by REDHAT-BUG-2210186?
Versions of LibreOffice up to and including 7.4.6 and 7.5.1 are affected by REDHAT-BUG-2210186.
What kind of vulnerability is REDHAT-BUG-2210186?
REDHAT-BUG-2210186 is identified as an Improper Validation of Array Index vulnerability.
What could happen if REDHAT-BUG-2210186 is exploited?
If exploited, REDHAT-BUG-2210186 could lead to potential crashes or unintended behavior in LibreOffice when processing malicious spreadsheet documents.