First published: Wed Jul 17 2019(Updated: )
Nils Emmerich discovered that LibreOffice incorrectly handled LibreLogo scripts. If a user were tricked into opening a specially crafted document, a remote attacker could cause LibreOffice to execute arbitrary code. (CVE-2019-9848) Matei "Mal" Badanoiu discovered that LibreOffice incorrectly handled stealth mode. Contrary to expectations, bullet graphics could be retrieved from remote locations when running in stealth mode. (CVE-2019-9849)
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
ubuntu/libreoffice-core | <1:6.2.5-0ubuntu0.19.04.1 | 1:6.2.5-0ubuntu0.19.04.1 |
Ubuntu OpenSSH Client | =19.04 | |
All of | ||
ubuntu/libreoffice-core | <1:6.0.7-0ubuntu0.18.04.8 | 1:6.0.7-0ubuntu0.18.04.8 |
Ubuntu OpenSSH Client | =18.04 | |
All of | ||
ubuntu/libreoffice-core | <1:5.1.6~rc2-0ubuntu1~xenial8 | 1:5.1.6~rc2-0ubuntu1~xenial8 |
Ubuntu OpenSSH Client | =16.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this advisory is CVE-2019-9848.
The severity of CVE-2019-9848 is high.
An attacker can exploit CVE-2019-9848 by tricking a user into opening a specially crafted document, which can cause LibreOffice to execute arbitrary code.
LibreOffice versions 5.1.6~rc2-0ubuntu1~xenial8, 6.0.7-0ubuntu0.18.04.8, and 6.2.5-0ubuntu0.19.04.1 are affected.
To fix the CVE-2019-9848 vulnerability, you should update to LibreOffice version 6.2.5-0ubuntu0.19.04.1 (for Ubuntu 19.04), 6.0.7-0ubuntu0.18.04.8 (for Ubuntu 18.04), or 5.1.6~rc2-0ubuntu1~xenial8 (for Ubuntu 16.04).