Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

Mageia: 2019-0340 Moderate: LibreOffice Script Execution Risks

mageia
Calendar Grey November 30, 2019
Dist Mageia Esm H88
Recent LibreOffice updates address several security issues linked to script execution flaws on Mageia platforms.
Updated libreoffice packages fix security vulnerabilities: LibreOffice has a feature where documents can specify that pre-installed scripts can be executed on various document eve...

Summary

Updated libreoffice packages fix security vulnerabilities:
LibreOffice has a feature where documents can specify that pre-installed scripts can be executed on various document events such as mouse-over, etc. LibreOffice is typically also bundled with LibreLogo, a programmable turtle vector graphics script, which can be manipulated into executing arbitrary python commands. By using the document event feature to trigger LibreLogo to execute python contained within a document a malicious document could be constructed which would execute arbitrary python commands silently without warning. In the fixed versions, LibreLogo cannot be called from a document event handler (CVE-2019-9848).
LibreOffice has a 'stealth mode' in which only documents from locations deemed 'trusted' are allowed to retrieve remote resources. This mode is not the default mode, but can be enabled by users who want to disable LibreOffice's ability to include remote resources within a document. A flaw existed where bull...

Read the Full Advisory

References

- https://bugs.mageia.org/show_bug.cgi?id=25154

-

-

-

-

-

-

-

- https://www.cve.org/CVERecord?id=CVE-2019-9848

- https://www.cve.org/CVERecord?id=CVE-2019-9849

- https://www.cve.org/CVERecord?id=CVE-2019-9850

- https://www.cve.org/CVERecord?id=CVE-2019-9851

- https://www.cve.org/CVERecord?id=CVE-2019-9852

- https://www.cve.org/CVERecord?id=CVE-2019-9853

- https://www.cve.org/CVERecord?id=CVE-2019-9854

Resolution

SRPMS

- 7/core/libreoffice-6.2.8.2-1.mga7

Severity
important
Lowest
Low
Medium
High
Critical

Publication date: 30 Nov 2019
URL: https://advisories.mageia.org/MGASA-2019-0340.html
Type: security
CVE: CVE-2019-9848, CVE-2019-9849, CVE-2019-9850, CVE-2019-9851, CVE-2019-9852, CVE-2019-9853, CVE-2019-9854

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here