CVE-2012-5639
published 2019-12-20CVE-2012-5639: LibreOffice and OpenOffice automatically open embedded content
PriorityP430medium6.5CVSS 3.1
AVNACLPRNUIRSUCHINAN
EPSS
5.84%
92.4th percentile
LibreOffice and OpenOffice automatically open embedded content
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | libreoffice | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
osv6.5MEDIUM
vendor_debian6.5LOW
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
OpenOffice: automatic opening of embedded external data
vendor_redhat·2012-12-13·CVSS 6.5
CVE-2012-5639 [MEDIUM] OpenOffice: automatic opening of embedded external data
OpenOffice: automatic opening of embedded external data
LibreOffice and OpenOffice automatically open embedded content
Package: openoffice.org (Red Hat Enterprise Linux 5) - Affected
Package: libreoffice (Red Hat Enterprise Linux 6) - Affected
Package: openoffice.org (Red Hat Enterprise Linux 6) - Affected
Debian
CVE-2012-5639: libreoffice - LibreOffice and OpenOffice automatically open embedded content
vendor_debian·2012·CVSS 6.5
CVE-2012-5639 [MEDIUM] CVE-2012-5639: libreoffice - LibreOffice and OpenOffice automatically open embedded content
LibreOffice and OpenOffice automatically open embedded content
Scope: local
bookworm: open
bullseye: open
forky: open
sid: open
trixie: open
GHSA
GHSA-rvg2-vh9m-cq32: LibreOffice and OpenOffice automatically open embedded content
ghsa_unreviewed·2022-04-23
CVE-2012-5639 [MEDIUM] CWE-20 GHSA-rvg2-vh9m-cq32: LibreOffice and OpenOffice automatically open embedded content
LibreOffice and OpenOffice automatically open embedded content
OSV
CVE-2012-5639: LibreOffice and OpenOffice automatically open embedded content
osv·2019-12-20·CVSS 6.5
CVE-2012-5639 [MEDIUM] CVE-2012-5639: LibreOffice and OpenOffice automatically open embedded content
LibreOffice and OpenOffice automatically open embedded content
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2012-5639 LibreOffice / OpenOffice: automatic opening of embedded external data [fedora-all]
bugzilla·2012-12-15·CVSS 6.5
CVE-2012-5639 [MEDIUM] CVE-2012-5639 LibreOffice / OpenOffice: automatic opening of embedded external data [fedora-all]
CVE-2012-5639 LibreOffice / OpenOffice: automatic opening of embedded external data [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please n
Bugzilla
CVE-2012-5639 LibreOffice / OpenOffice: automatic opening of embedded external data [fedora-all]
bugzilla·2012-12-15·CVSS 6.5
CVE-2012-5639 [MEDIUM] CVE-2012-5639 LibreOffice / OpenOffice: automatic opening of embedded external data [fedora-all]
CVE-2012-5639 LibreOffice / OpenOffice: automatic opening of embedded external data [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please n
Bugzilla
CVE-2012-5639 LibreOffice / OpenOffice: automatic opening of embedded external data
bugzilla·2012-12-15·CVSS 6.5
CVE-2012-5639 [MEDIUM] CVE-2012-5639 LibreOffice / OpenOffice: automatic opening of embedded external data
CVE-2012-5639 LibreOffice / OpenOffice: automatic opening of embedded external data
Timo Warns ([email protected]) reported publicly that OpenOffice and
LibreOffice (as well as other Office Suites) fail to appropriately warn users
when a file with embedded content is opened. Additionally it is not possible
to disable the opening of embedded content within files. This can be used to
add tracking behavior to files or to deliver additional files that can
potentially exploit other security issues when parsed to the user.
Additionally if the file is converted (e.g. to a PDF) and then saved the
converted file may contain a direct copy of the embedded data, thus if
something sensitive if referenced (such as ~/.ssh/id_rsa) this information may
then be exposed if the resulting file is shared.
D
http://www.openwall.com/lists/oss-security/2012/12/14/1http://www.openwall.com/lists/oss-security/2023/12/28/6http://www.openwall.com/lists/oss-security/2024/01/03/6http://www.openwall.com/lists/oss-security/2024/01/03/7https://access.redhat.com/security/cve/cve-2012-5639https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2012-5639https://lists.apache.org/thread.html/r253f92d0e6511d07a79774002e1d9db1d20b24bff27914a5adb14ccb%40%3Cissues.openoffice.apache.org%3Ehttps://security-tracker.debian.org/tracker/CVE-2012-5639http://www.openwall.com/lists/oss-security/2012/12/14/1http://www.openwall.com/lists/oss-security/2023/12/28/6http://www.openwall.com/lists/oss-security/2024/01/03/6http://www.openwall.com/lists/oss-security/2024/01/03/7https://access.redhat.com/security/cve/cve-2012-5639https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2012-5639https://lists.apache.org/thread.html/r253f92d0e6511d07a79774002e1d9db1d20b24bff27914a5adb14ccb%40%3Cissues.openoffice.apache.org%3Ehttps://security-tracker.debian.org/tracker/CVE-2012-5639
2019-12-20
Published