First published: Tue Mar 04 2025(Updated: )
LibreOffice supports Office URI Schemes to enable browser integration of LibreOffice with MS SharePoint server. An additional scheme 'vnd.libreoffice.command' specific to LibreOffice was added. In the affected versions of LibreOffice a link in a browser using that scheme could be constructed with an embedded inner URL that when passed to LibreOffice could call internal macros with arbitrary arguments. This issue affects LibreOffice: from 24.8 before < 24.8.5, from 25.2 before < 25.2.1.
Affected Software | Affected Version | How to fix |
---|---|---|
LibreOffice Draw | >24.8<24.8.5 | |
LibreOffice Draw | >25.2<25.2.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of REDHAT-BUG-2349906 is classified as moderate.
To fix REDHAT-BUG-2349906, update to the latest version of LibreOffice that addresses this vulnerability.
REDHAT-BUG-2349906 affects LibreOffice versions from 24.8 to 24.8.5 and from 25.2 to 25.2.1.
REDHAT-BUG-2349906 can be exploited through specially crafted browser links utilizing the 'vnd.libreoffice.command' scheme.
As of now, there is no official workaround for REDHAT-BUG-2349906, and it is recommended to apply the appropriate updates.