CVE Database
/

CVE-2019-9854

Back to search

CVE-2019-9854

Published: Sep 6, 2019

Modified: Sep 16, 2024

PUBLISHED

Description

LibreOffice has a feature where documents can specify that pre-installed macros can be executed on various script events such as mouse-over, document-open etc. Access is intended to be restricted to scripts under the share/Scripts/python, user/Scripts/python sub-directories of the LibreOffice install. Protection was added, to address CVE-2019-9852, to avoid a directory traversal attack where scripts in arbitrary locations on the file system could be executed by employing a URL encoding attack to defeat the path verification step. However this protection could be bypassed by taking advantage of a flaw in how LibreOffice assembled the final script URL location directly from components of the passed in path as opposed to solely from the sanitized output of the path verification step. This issue affects: Document Foundation LibreOffice 6.2 versions prior to 6.2.7; 6.3 versions prior to 6.3.1.

VendorProductVersions

Document Foundation

LibreOffice

affected
6.2 - < 6.2.7
affected
6.3 - < 6.3.1

References

DSA-4519
vendor-advisory
x_refsource_DEBIAN
FEDORA-2019-9627e1402e
vendor-advisory
x_refsource_FEDORA
USN-4138-1
vendor-advisory
x_refsource_UBUNTU
openSUSE-SU-2019:2183
vendor-advisory
x_refsource_SUSE
openSUSE-SU-2019:2361
vendor-advisory
x_refsource_SUSE

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now