CVE-2014-0247
published 2014-07-03CVE-2014-0247: LibreOffice 4.2.4 executes unspecified VBA macros automatically, which has unspecified impact and attack vectors, possibly related to doc/docmacromode.cxx.
PriorityP337critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
3.92%
89.2th percentile
LibreOffice 4.2.4 executes unspecified VBA macros automatically, which has unspecified impact and attack vectors, possibly related to doc/docmacromode.cxx.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| debian | libreoffice | < libreoffice 1:4.2.5-1 (bookworm) | libreoffice 1:4.2.5-1 (bookworm) |
| fedoraproject | fedora | — | — |
| libreoffice | libreoffice | — | — |
| libreoffice | libreoffice | >= 0 < 1:4.2.5-1 | 1:4.2.5-1 |
| libreoffice | libreoffice | >= 0 < 1:4.2.5-1 | 1:4.2.5-1 |
| libreoffice | libreoffice | >= 0 < 1:4.2.5-1 | 1:4.2.5-1 |
| libreoffice | libreoffice | >= 0 < 1:4.2.5-1 | 1:4.2.5-1 |
| opensuse | opensuse | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_workstation | — | — |
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
osv10.0CRITICAL
vendor_debian10.0CRITICAL
vendor_redhat10.0CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
libreoffice: VBA macros executed unconditionally
vendor_redhat·2014-06-23·CVSS 10.0
CVE-2014-0247 [CRITICAL] CWE-356 libreoffice: VBA macros executed unconditionally
libreoffice: VBA macros executed unconditionally
LibreOffice 4.2.4 executes unspecified VBA macros automatically, which has unspecified impact and attack vectors, possibly related to doc/docmacromode.cxx.
It was found that LibreOffice documents executed macros unconditionally, without user approval, when these documents were opened using LibreOffice. An attacker could use this flaw to execute arbitrary code as the user running LibreOffice by embedding malicious VBA scripts in the document as macros.
Package: libreoffice (Red Hat Enterprise Linux 6) - Not affected
Ubuntu
LibreOffice vulnerability
vendor_ubuntu·2014-06-23
CVE-2014-0247 LibreOffice vulnerability
Title: LibreOffice vulnerability
Summary: LibreOffice would unconditionally execute certain VBA macros.
It was discovered that LibreOffice unconditionally executed certain VBA
macros, contrary to user expectations.
Instructions: After a standard system update you need to restart LibreOffice to makea all
the necessary changes.
Debian
CVE-2014-0247: libreoffice - LibreOffice 4.2.4 executes unspecified VBA macros automatically, which has unspe...
vendor_debian·2014·CVSS 10.0
CVE-2014-0247 [CRITICAL] CVE-2014-0247: libreoffice - LibreOffice 4.2.4 executes unspecified VBA macros automatically, which has unspe...
LibreOffice 4.2.4 executes unspecified VBA macros automatically, which has unspecified impact and attack vectors, possibly related to doc/docmacromode.cxx.
Scope: local
bookworm: resolved (fixed in 1:4.2.5-1)
bullseye: resolved (fixed in 1:4.2.5-1)
forky: resolved (fixed in 1:4.2.5-1)
sid: resolved (fixed in 1:4.2.5-1)
trixie: resolved (fixed in 1:4.2.5-1)
GHSA
GHSA-42hf-67vj-j9w8: LibreOffice 4
ghsa_unreviewed·2022-05-14
CVE-2014-0247 [HIGH] GHSA-42hf-67vj-j9w8: LibreOffice 4
LibreOffice 4.2.4 executes unspecified VBA macros automatically, which has unspecified impact and attack vectors, possibly related to doc/docmacromode.cxx.
OSV
CVE-2014-0247: LibreOffice 4
osv·2014-07-03·CVSS 10.0
CVE-2014-0247 [CRITICAL] CVE-2014-0247: LibreOffice 4
LibreOffice 4.2.4 executes unspecified VBA macros automatically, which has unspecified impact and attack vectors, possibly related to doc/docmacromode.cxx.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-0247 libreoffice: VBA macros executed unconditionally [fedora-all]
bugzilla·2014-06-24·CVSS 10.0
CVE-2014-0247 [CRITICAL] CVE-2014-0247 libreoffice: VBA macros executed unconditionally [fedora-all]
CVE-2014-0247 libreoffice: VBA macros executed unconditionally [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, use the bodhi submission link noted
in the next comment(s). This will include the bug IDs of this tracking
bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
NOTE: this issue affects multiple su
Bugzilla
CVE-2014-0247 libreoffice: VBA macros executed unconditionally
bugzilla·2014-06-19·CVSS 10.0
CVE-2014-0247 [CRITICAL] CVE-2014-0247 libreoffice: VBA macros executed unconditionally
CVE-2014-0247 libreoffice: VBA macros executed unconditionally
It was found that LibreOffice documents executed macros unconditionally, without user approval, when these documents were opened using LibreOffice. A attacker could use this flaw to execute arbitray code as the user running LibreOffice, by embedding malicious VBA scripts in the document as macros.
The following commit fixes this issue:
http://cgit.freedesktop.org/libreoffice/core/commit/?id=1b0402f87c9b17fef2141130bfaa1798ece6ba0d
Discussion:
This issue is public now.
---
Created libreoffice tracking bugs for this issue:
Affects: fedora-all [bug 1112450]
---
Statement:
(none)
---
libreoffice-4.1.6.2-7.fc19 has been pushed to the Fedora 19 stable repository. If problems still persist, please make note of it in this b
http://lists.fedoraproject.org/pipermail/package-announce/2014-July/135020.htmlhttp://lists.opensuse.org/opensuse-updates/2014-07/msg00006.htmlhttp://people.canonical.com/~ubuntu-security/cve/2014/CVE-2014-0247.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0377.htmlhttp://secunia.com/advisories/57383http://secunia.com/advisories/59330http://secunia.com/advisories/60799http://www.gentoo.org/security/en/glsa/glsa-201408-19.xmlhttp://www.securityfocus.com/bid/68151http://www.ubuntu.com/usn/USN-2253-1https://bugs.mageia.org/show_bug.cgi?id=13580https://gerrit.libreoffice.org/gitweb?p=core.git%3Ba=blobdiff%3Bf=sfx2/source/doc/docmacromode.cxx%3Bh=4d4ae52b4339582a039744d03671c1db0633d6c3%3Bhp=2108d1920f8148ff60fd4a57684f295d6d733e7b%3Bhb=1b0402f87c9b17fef2141130bfaa1798ece6ba0d%3Bhpb=4d2113250fa7ed62fe2c53ed0f76e3de5875cb81https://www.libreoffice.org/about-us/security/advisories/cve-2014-0247/http://lists.fedoraproject.org/pipermail/package-announce/2014-July/135020.htmlhttp://lists.opensuse.org/opensuse-updates/2014-07/msg00006.htmlhttp://people.canonical.com/~ubuntu-security/cve/2014/CVE-2014-0247.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0377.htmlhttp://secunia.com/advisories/57383http://secunia.com/advisories/59330http://secunia.com/advisories/60799http://www.gentoo.org/security/en/glsa/glsa-201408-19.xmlhttp://www.securityfocus.com/bid/68151http://www.ubuntu.com/usn/USN-2253-1https://bugs.mageia.org/show_bug.cgi?id=13580https://gerrit.libreoffice.org/gitweb?p=core.git%3Ba=blobdiff%3Bf=sfx2/source/doc/docmacromode.cxx%3Bh=4d4ae52b4339582a039744d03671c1db0633d6c3%3Bhp=2108d1920f8148ff60fd4a57684f295d6d733e7b%3Bhb=1b0402f87c9b17fef2141130bfaa1798ece6ba0d%3Bhpb=4d2113250fa7ed62fe2c53ed0f76e3de5875cb81https://www.libreoffice.org/about-us/security/advisories/cve-2014-0247/
2014-07-03
Published