cbcvebase.
CVE-2023-1183
published 2023-07-10

CVE-2023-1183: A flaw was found in the Libreoffice package. An attacker can craft an odb containing a "database/script" file with a SCRIPT command where the contents of the…

medium5.5CVSS 3.1
AVLACLPRNUIRSUCNIHAN
A flaw was found in the Libreoffice package. An attacker can craft an odb containing a "database/script" file with a SCRIPT command where the contents of the file could be written to a new file whose location was determined by the attacker.

Affected

7 ranges
VendorProductVersion rangeFixed in
debianhsqldb< hsqldb 2.7.1-1+deb12u1 (bookworm)hsqldb 2.7.1-1+deb12u1 (bookworm)
debianhsqldb1.8.0< hsqldb 2.7.1-1+deb12u1 (bookworm)hsqldb 2.7.1-1+deb12u1 (bookworm)
fedoraprojectfedora
libreofficelibreoffice< 7.4.67.4.6
libreofficelibreoffice
redhatenterprise_linux
redhatenterprise_linux

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
osv5.5MEDIUM