CVE-2019-9854Improper Access Control in Foundation Libreoffice

Severity
7.8HIGHNVD
EPSS
0.8%
top 26.63%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 6
Latest updateMay 24

Description

LibreOffice has a feature where documents can specify that pre-installed macros can be executed on various script events such as mouse-over, document-open etc. Access is intended to be restricted to scripts under the share/Scripts/python, user/Scripts/python sub-directories of the LibreOffice install. Protection was added, to address CVE-2019-9852, to avoid a directory traversal attack where scripts in arbitrary locations on the file system could be executed by employing a URL encoding attack to

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages5 packages

CVEListV5document_foundation/libreoffice6.26.2.7+1
debiandebian/libreoffice< libreoffice 1:6.3.1~rc2-1 (bookworm)
NVDlibreoffice/libreoffice6.2.06.2.7+1
Debianlibreoffice/libreoffice< 1:6.3.1~rc2-1+3
NVDopensuse/leap15.0, 15.1+1

Also affects: Debian Linux 10.0, 8.0, 9.0, Fedora 29, Ubuntu Linux 16.04, 18.04, 19.04, Enterprise Linux 7.0, 8.0

🔴Vulnerability Details

3
GHSA
GHSA-54x7-phmv-8vq8: LibreOffice has a feature where documents can specify that pre-installed macros can be executed on various script events such as mouse-over, document-2022-05-24
OSV
CVE-2019-9854: LibreOffice has a feature where documents can specify that pre-installed macros can be executed on various script events such as mouse-over, document-2019-09-06
CVEList
Unsafe URL assembly flaw in allowed script location check2019-09-06

📋Vendor Advisories

3
Ubuntu
LibreOffice vulnerability2019-09-24
Red Hat
libreoffice: Unsafe URL assembly flaw in allowed script location check2019-09-06
Debian
CVE-2019-9854: libreoffice - LibreOffice has a feature where documents can specify that pre-installed macros ...2019

💬Community

2
Bugzilla
CVE-2019-9854 libreoffice: Unsafe URL assembly flaw in allowed script location check2019-11-07
Bugzilla
CVE-2019-9854 libreoffice: unsafe URL assembly flaw in allowed script location check [fedora-all]2019-11-07