vulnerability

Red Hat: CVE-2019-9848: Moderate: libreoffice security and bug fix update (RHSA-2020:1151)

Severity
8
CVSS
(AV:N/AC:L/Au:N/C:P/I:P/A:P)
Published
2019-07-17
Added
2020-04-01
Modified
2021-03-03

Description

LibreOffice has a feature where documents can specify that pre-installed scripts can be executed on various document events such as mouse-over, etc. LibreOffice is typically also bundled with LibreLogo, a programmable turtle vector graphics script, which can be manipulated into executing arbitrary python commands. By using the document event feature to trigger LibreLogo to execute python contained within a document a malicious document could be constructed which would execute arbitrary python commands silently without warning. In the fixed versions, LibreLogo cannot be called from a document event handler. This issue affects: Document Foundation LibreOffice versions prior to 6.2.5.

Solution(s)

redhat-upgrade-autocorr-afredhat-upgrade-autocorr-bgredhat-upgrade-autocorr-caredhat-upgrade-autocorr-csredhat-upgrade-autocorr-daredhat-upgrade-autocorr-deredhat-upgrade-autocorr-enredhat-upgrade-autocorr-esredhat-upgrade-autocorr-faredhat-upgrade-autocorr-firedhat-upgrade-autocorr-frredhat-upgrade-autocorr-garedhat-upgrade-autocorr-hrredhat-upgrade-autocorr-huredhat-upgrade-autocorr-isredhat-upgrade-autocorr-itredhat-upgrade-autocorr-jaredhat-upgrade-autocorr-koredhat-upgrade-autocorr-lbredhat-upgrade-autocorr-ltredhat-upgrade-autocorr-mnredhat-upgrade-autocorr-nlredhat-upgrade-autocorr-plredhat-upgrade-autocorr-ptredhat-upgrade-autocorr-roredhat-upgrade-autocorr-ruredhat-upgrade-autocorr-skredhat-upgrade-autocorr-slredhat-upgrade-autocorr-srredhat-upgrade-autocorr-svredhat-upgrade-autocorr-trredhat-upgrade-autocorr-viredhat-upgrade-autocorr-zhredhat-upgrade-libreofficeredhat-upgrade-libreoffice-baseredhat-upgrade-libreoffice-bshredhat-upgrade-libreoffice-calcredhat-upgrade-libreoffice-coreredhat-upgrade-libreoffice-dataredhat-upgrade-libreoffice-debuginforedhat-upgrade-libreoffice-drawredhat-upgrade-libreoffice-emailmergeredhat-upgrade-libreoffice-filtersredhat-upgrade-libreoffice-gdb-debug-supportredhat-upgrade-libreoffice-gladeredhat-upgrade-libreoffice-graphicfilterredhat-upgrade-libreoffice-gtk2redhat-upgrade-libreoffice-gtk3redhat-upgrade-libreoffice-help-arredhat-upgrade-libreoffice-help-bgredhat-upgrade-libreoffice-help-bnredhat-upgrade-libreoffice-help-caredhat-upgrade-libreoffice-help-csredhat-upgrade-libreoffice-help-daredhat-upgrade-libreoffice-help-deredhat-upgrade-libreoffice-help-dzredhat-upgrade-libreoffice-help-elredhat-upgrade-libreoffice-help-esredhat-upgrade-libreoffice-help-etredhat-upgrade-libreoffice-help-euredhat-upgrade-libreoffice-help-firedhat-upgrade-libreoffice-help-frredhat-upgrade-libreoffice-help-glredhat-upgrade-libreoffice-help-guredhat-upgrade-libreoffice-help-heredhat-upgrade-libreoffice-help-hiredhat-upgrade-libreoffice-help-hrredhat-upgrade-libreoffice-help-huredhat-upgrade-libreoffice-help-idredhat-upgrade-libreoffice-help-itredhat-upgrade-libreoffice-help-jaredhat-upgrade-libreoffice-help-koredhat-upgrade-libreoffice-help-ltredhat-upgrade-libreoffice-help-lvredhat-upgrade-libreoffice-help-nbredhat-upgrade-libreoffice-help-nlredhat-upgrade-libreoffice-help-nnredhat-upgrade-libreoffice-help-plredhat-upgrade-libreoffice-help-pt-brredhat-upgrade-libreoffice-help-pt-ptredhat-upgrade-libreoffice-help-roredhat-upgrade-libreoffice-help-ruredhat-upgrade-libreoffice-help-siredhat-upgrade-libreoffice-help-skredhat-upgrade-libreoffice-help-slredhat-upgrade-libreoffice-help-svredhat-upgrade-libreoffice-help-taredhat-upgrade-libreoffice-help-trredhat-upgrade-libreoffice-help-ukredhat-upgrade-libreoffice-help-zh-hansredhat-upgrade-libreoffice-help-zh-hantredhat-upgrade-libreoffice-impressredhat-upgrade-libreoffice-langpack-enredhat-upgrade-libreoffice-librelogoredhat-upgrade-libreoffice-mathredhat-upgrade-libreoffice-nlpsolverredhat-upgrade-libreoffice-officebeanredhat-upgrade-libreoffice-officebean-commonredhat-upgrade-libreoffice-ogltransredhat-upgrade-libreoffice-opensymbol-fontsredhat-upgrade-libreoffice-pdfimportredhat-upgrade-libreoffice-postgresqlredhat-upgrade-libreoffice-pyunoredhat-upgrade-libreoffice-rhinoredhat-upgrade-libreoffice-sdkredhat-upgrade-libreoffice-sdk-docredhat-upgrade-libreoffice-ureredhat-upgrade-libreoffice-ure-commonredhat-upgrade-libreoffice-wiki-publisherredhat-upgrade-libreoffice-writerredhat-upgrade-libreoffice-x11redhat-upgrade-libreoffice-xsltfilterredhat-upgrade-libreofficekitredhat-upgrade-libreofficekit-devel
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.