CVE-2023-0950Improper Validation of Array Index in Document Foundation Libreoffice

Severity
7.8HIGHNVD
EPSS
0.1%
top 80.49%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 25
Latest updateJun 7

Description

Improper Validation of Array Index vulnerability in the spreadsheet component of The Document Foundation LibreOffice allows an attacker to craft a spreadsheet document that will cause an array index underflow when loaded. In the affected versions of LibreOffice certain malformed spreadsheet formulas, such as AGGREGATE, could be created with less parameters passed to the formula interpreter than it expected, leading to an array index underflow, in which case there is a risk that arbitrary code co

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages4 packages

CVEListV5the_document_foundation/libreoffice7.47.4.6+1
NVDlibreoffice/libreoffice7.4.07.4.6+1
Debianlibreoffice/libreoffice< 1:7.0.4-4+deb11u7+3
Ubuntulibreoffice/libreoffice< 1:6.4.7-0ubuntu0.20.04.8+1

Also affects: Debian Linux 10.0

🔴Vulnerability Details

4
OSV
libreoffice vulnerabilities2023-06-07
GHSA
GHSA-qv23-hw3g-384q: Improper Validation of Array Index vulnerability in the spreadsheet component of The Document Foundation LibreOffice allows an attacker to craft a spr2023-05-25
OSV
CVE-2023-0950: Improper Validation of Array Index vulnerability in the spreadsheet component of The Document Foundation LibreOffice allows an attacker to craft a spr2023-05-25
CVEList
Array Index UnderFlow in Calc Formula Parsing2023-05-25

📋Vendor Advisories

3
Ubuntu
LibreOffice vulnerabilities2023-06-07
Red Hat
libreoffice: Array index underflow in Calc formula parsing2023-05-25
Debian
CVE-2023-0950: libreoffice - Improper Validation of Array Index vulnerability in the spreadsheet component of...2023
CVE-2023-0950 — Improper Validation of Array Index | cvebase