vulnerability

Red Hat: CVE-2019-9851: CVE-2019-9851 libreoffice: LibreLogo global-event script execution (Multiple Advisories)

Severity
8
CVSS
(AV:N/AC:L/Au:N/C:P/I:P/A:P)
Published
2019-08-15
Added
2020-04-01
Modified
2024-11-27

Description

LibreOffice is typically bundled with LibreLogo, a programmable turtle vector graphics script, which can execute arbitrary python commands contained with the document it is launched from. Protection was added, to address CVE-2019-9848, to block calling LibreLogo from document event script handers, e.g. mouse over. However LibreOffice also has a separate feature where documents can specify that pre-installed scripts can be executed on various global script events such as document-open, etc. In the fixed versions, global script event handlers are validated equivalently to document script event handlers. This issue affects: Document Foundation LibreOffice versions prior to 6.2.6.

Solution(s)

redhat-upgrade-autocorr-afredhat-upgrade-autocorr-bgredhat-upgrade-autocorr-caredhat-upgrade-autocorr-csredhat-upgrade-autocorr-daredhat-upgrade-autocorr-deredhat-upgrade-autocorr-enredhat-upgrade-autocorr-esredhat-upgrade-autocorr-faredhat-upgrade-autocorr-firedhat-upgrade-autocorr-frredhat-upgrade-autocorr-garedhat-upgrade-autocorr-hrredhat-upgrade-autocorr-huredhat-upgrade-autocorr-isredhat-upgrade-autocorr-itredhat-upgrade-autocorr-jaredhat-upgrade-autocorr-koredhat-upgrade-autocorr-lbredhat-upgrade-autocorr-ltredhat-upgrade-autocorr-mnredhat-upgrade-autocorr-nlredhat-upgrade-autocorr-plredhat-upgrade-autocorr-ptredhat-upgrade-autocorr-roredhat-upgrade-autocorr-ruredhat-upgrade-autocorr-skredhat-upgrade-autocorr-slredhat-upgrade-autocorr-srredhat-upgrade-autocorr-svredhat-upgrade-autocorr-trredhat-upgrade-autocorr-viredhat-upgrade-autocorr-zhredhat-upgrade-libreofficeredhat-upgrade-libreoffice-baseredhat-upgrade-libreoffice-base-debuginforedhat-upgrade-libreoffice-bshredhat-upgrade-libreoffice-calcredhat-upgrade-libreoffice-calc-debuginforedhat-upgrade-libreoffice-coreredhat-upgrade-libreoffice-core-debuginforedhat-upgrade-libreoffice-dataredhat-upgrade-libreoffice-debuginforedhat-upgrade-libreoffice-debugsourceredhat-upgrade-libreoffice-drawredhat-upgrade-libreoffice-emailmergeredhat-upgrade-libreoffice-filtersredhat-upgrade-libreoffice-gdb-debug-supportredhat-upgrade-libreoffice-gladeredhat-upgrade-libreoffice-glade-debuginforedhat-upgrade-libreoffice-graphicfilterredhat-upgrade-libreoffice-graphicfilter-debuginforedhat-upgrade-libreoffice-gtk2redhat-upgrade-libreoffice-gtk2-debuginforedhat-upgrade-libreoffice-gtk3redhat-upgrade-libreoffice-gtk3-debuginforedhat-upgrade-libreoffice-help-arredhat-upgrade-libreoffice-help-bgredhat-upgrade-libreoffice-help-bnredhat-upgrade-libreoffice-help-caredhat-upgrade-libreoffice-help-csredhat-upgrade-libreoffice-help-daredhat-upgrade-libreoffice-help-deredhat-upgrade-libreoffice-help-dzredhat-upgrade-libreoffice-help-elredhat-upgrade-libreoffice-help-enredhat-upgrade-libreoffice-help-esredhat-upgrade-libreoffice-help-etredhat-upgrade-libreoffice-help-euredhat-upgrade-libreoffice-help-firedhat-upgrade-libreoffice-help-frredhat-upgrade-libreoffice-help-glredhat-upgrade-libreoffice-help-guredhat-upgrade-libreoffice-help-heredhat-upgrade-libreoffice-help-hiredhat-upgrade-libreoffice-help-hrredhat-upgrade-libreoffice-help-huredhat-upgrade-libreoffice-help-idredhat-upgrade-libreoffice-help-itredhat-upgrade-libreoffice-help-jaredhat-upgrade-libreoffice-help-koredhat-upgrade-libreoffice-help-ltredhat-upgrade-libreoffice-help-lvredhat-upgrade-libreoffice-help-nbredhat-upgrade-libreoffice-help-nlredhat-upgrade-libreoffice-help-nnredhat-upgrade-libreoffice-help-plredhat-upgrade-libreoffice-help-pt-brredhat-upgrade-libreoffice-help-pt-ptredhat-upgrade-libreoffice-help-roredhat-upgrade-libreoffice-help-ruredhat-upgrade-libreoffice-help-siredhat-upgrade-libreoffice-help-skredhat-upgrade-libreoffice-help-slredhat-upgrade-libreoffice-help-svredhat-upgrade-libreoffice-help-taredhat-upgrade-libreoffice-help-trredhat-upgrade-libreoffice-help-ukredhat-upgrade-libreoffice-help-zh-hansredhat-upgrade-libreoffice-help-zh-hantredhat-upgrade-libreoffice-impressredhat-upgrade-libreoffice-impress-debuginforedhat-upgrade-libreoffice-langpack-afredhat-upgrade-libreoffice-langpack-arredhat-upgrade-libreoffice-langpack-asredhat-upgrade-libreoffice-langpack-bgredhat-upgrade-libreoffice-langpack-bnredhat-upgrade-libreoffice-langpack-brredhat-upgrade-libreoffice-langpack-caredhat-upgrade-libreoffice-langpack-csredhat-upgrade-libreoffice-langpack-cyredhat-upgrade-libreoffice-langpack-daredhat-upgrade-libreoffice-langpack-deredhat-upgrade-libreoffice-langpack-dzredhat-upgrade-libreoffice-langpack-elredhat-upgrade-libreoffice-langpack-enredhat-upgrade-libreoffice-langpack-esredhat-upgrade-libreoffice-langpack-etredhat-upgrade-libreoffice-langpack-euredhat-upgrade-libreoffice-langpack-faredhat-upgrade-libreoffice-langpack-firedhat-upgrade-libreoffice-langpack-frredhat-upgrade-libreoffice-langpack-garedhat-upgrade-libreoffice-langpack-glredhat-upgrade-libreoffice-langpack-guredhat-upgrade-libreoffice-langpack-heredhat-upgrade-libreoffice-langpack-hiredhat-upgrade-libreoffice-langpack-hrredhat-upgrade-libreoffice-langpack-huredhat-upgrade-libreoffice-langpack-idredhat-upgrade-libreoffice-langpack-itredhat-upgrade-libreoffice-langpack-jaredhat-upgrade-libreoffice-langpack-kkredhat-upgrade-libreoffice-langpack-knredhat-upgrade-libreoffice-langpack-koredhat-upgrade-libreoffice-langpack-ltredhat-upgrade-libreoffice-langpack-lvredhat-upgrade-libreoffice-langpack-mairedhat-upgrade-libreoffice-langpack-mlredhat-upgrade-libreoffice-langpack-mrredhat-upgrade-libreoffice-langpack-nbredhat-upgrade-libreoffice-langpack-nlredhat-upgrade-libreoffice-langpack-nnredhat-upgrade-libreoffice-langpack-nrredhat-upgrade-libreoffice-langpack-nsoredhat-upgrade-libreoffice-langpack-orredhat-upgrade-libreoffice-langpack-paredhat-upgrade-libreoffice-langpack-plredhat-upgrade-libreoffice-langpack-pt-brredhat-upgrade-libreoffice-langpack-pt-ptredhat-upgrade-libreoffice-langpack-roredhat-upgrade-libreoffice-langpack-ruredhat-upgrade-libreoffice-langpack-siredhat-upgrade-libreoffice-langpack-skredhat-upgrade-libreoffice-langpack-slredhat-upgrade-libreoffice-langpack-srredhat-upgrade-libreoffice-langpack-ssredhat-upgrade-libreoffice-langpack-stredhat-upgrade-libreoffice-langpack-svredhat-upgrade-libreoffice-langpack-taredhat-upgrade-libreoffice-langpack-teredhat-upgrade-libreoffice-langpack-thredhat-upgrade-libreoffice-langpack-tnredhat-upgrade-libreoffice-langpack-trredhat-upgrade-libreoffice-langpack-tsredhat-upgrade-libreoffice-langpack-ukredhat-upgrade-libreoffice-langpack-veredhat-upgrade-libreoffice-langpack-xhredhat-upgrade-libreoffice-langpack-zh-hansredhat-upgrade-libreoffice-langpack-zh-hantredhat-upgrade-libreoffice-langpack-zuredhat-upgrade-libreoffice-librelogoredhat-upgrade-libreoffice-mathredhat-upgrade-libreoffice-math-debuginforedhat-upgrade-libreoffice-nlpsolverredhat-upgrade-libreoffice-officebeanredhat-upgrade-libreoffice-officebean-commonredhat-upgrade-libreoffice-officebean-debuginforedhat-upgrade-libreoffice-ogltransredhat-upgrade-libreoffice-ogltrans-debuginforedhat-upgrade-libreoffice-opensymbol-fontsredhat-upgrade-libreoffice-pdfimportredhat-upgrade-libreoffice-pdfimport-debuginforedhat-upgrade-libreoffice-postgresqlredhat-upgrade-libreoffice-postgresql-debuginforedhat-upgrade-libreoffice-pyunoredhat-upgrade-libreoffice-pyuno-debuginforedhat-upgrade-libreoffice-rhinoredhat-upgrade-libreoffice-sdkredhat-upgrade-libreoffice-sdk-debuginforedhat-upgrade-libreoffice-sdk-docredhat-upgrade-libreoffice-ureredhat-upgrade-libreoffice-ure-commonredhat-upgrade-libreoffice-ure-debuginforedhat-upgrade-libreoffice-wiki-publisherredhat-upgrade-libreoffice-writerredhat-upgrade-libreoffice-writer-debuginforedhat-upgrade-libreoffice-x11redhat-upgrade-libreoffice-x11-debuginforedhat-upgrade-libreoffice-xsltfilterredhat-upgrade-libreofficekitredhat-upgrade-libreofficekit-debuginforedhat-upgrade-libreofficekit-devel
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.