CVE-2023-1183
published 2023-07-10CVE-2023-1183: A flaw was found in the Libreoffice package. An attacker can craft an odb containing a "database/script" file with a SCRIPT command where the contents of the…
PriorityP344medium5.5CVSS 3.1
AVLACLPRNUIRSUCNIHAN
EPSS
64.63%
99.2th percentile
A flaw was found in the Libreoffice package. An attacker can craft an odb containing a "database/script" file with a SCRIPT command where the contents of the file could be written to a new file whose location was determined by the attacker.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | hsqldb | < hsqldb 2.7.1-1+deb12u1 (bookworm) | hsqldb 2.7.1-1+deb12u1 (bookworm) |
| debian | hsqldb1.8.0 | < hsqldb 2.7.1-1+deb12u1 (bookworm) | hsqldb 2.7.1-1+deb12u1 (bookworm) |
| fedoraproject | fedora | — | — |
| libreoffice | libreoffice | < 7.4.6 | 7.4.6 |
| libreoffice | libreoffice | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Malicious .odb file containing a crafted 'database/script' file with a SCRIPT command used to achieve arbitrary file write ↗
- →Inspect .odb archives (ZIP format) for the presence of a 'database/script' entry containing SCRIPT commands, which is anomalous and indicative of exploitation attempts ↗
- ·Vulnerability is local scope only; attacker must deliver and have the victim open a malicious .odb file ↗
- ·Red Hat Enterprise Linux 6 is out of support scope and RHEL 7 will not receive a fix; patched versions are available for Debian (bookworm: 2.7.1-1+deb12u1, bullseye: 2.5.1-1+deb11u2) and Debian sid/trixie/forky (2.7.2-1) ↗
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
osv5.5MEDIUM
vendor_redhat5.5MEDIUM
vendor_debian5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kernel: drm/amdgpu: Fix possible NULL dereference in amdgpu_ras_query_error_status_helper()
vendor_redhat·2024-03-06·CVSS 5.5
CVE-2023-52585 [MEDIUM] CWE-476 kernel: drm/amdgpu: Fix possible NULL dereference in amdgpu_ras_query_error_status_helper()
kernel: drm/amdgpu: Fix possible NULL dereference in amdgpu_ras_query_error_status_helper()
In the Linux kernel, the following vulnerability has been resolved:
drm/amdgpu: Fix possible NULL dereference in amdgpu_ras_query_error_status_helper()
Return invalid error code -EINVAL for invalid block id.
Fixes the below:
drivers/gpu/drm/amd/amdgpu/amdgpu_ras.c:1183 amdgpu_ras_query_error_status_helper() error: we previously assumed 'info' could be null (see line 1176)
A vulnerability was found in the amdgpu_ras_query_error_status_helper() function in the Linunx kernel which could lead to a possible NULL pointer dereference, causing data corruption or crashes.
Statement: Red Hat Enterprise Linux 8 is not impacted by this vulnerability, as it does not contain the vulnerable amdgpu_ras_query_err
Red Hat
libreoffice: Arbitrary file write
vendor_redhat·2023-06-19·CVSS 5.0
CVE-2023-1183 [MEDIUM] CWE-20 libreoffice: Arbitrary file write
libreoffice: Arbitrary file write
A flaw was found in the Libreoffice package. An attacker can craft an odb containing a "database/script" file with a SCRIPT command where the contents of the file could be written to a new file whose location was determined by the attacker.
A flaw was found in the Libreoffice package. An attacker can craft an odb containing a "database/script" file with a SCRIPT command where the contents of the file could be written to a new file whose location was determined by the attacker.
Package: libreoffice (Red Hat Enterprise Linux 6) - Out of support scope
Package: libreoffice (Red Hat Enterprise Linux 7) - Will not fix
Debian
CVE-2023-1183: hsqldb - A flaw was found in the Libreoffice package. An attacker can craft an odb contai...
vendor_debian·2023·CVSS 5.0
CVE-2023-1183 [MEDIUM] CVE-2023-1183: hsqldb - A flaw was found in the Libreoffice package. An attacker can craft an odb contai...
A flaw was found in the Libreoffice package. An attacker can craft an odb containing a "database/script" file with a SCRIPT command where the contents of the file could be written to a new file whose location was determined by the attacker.
Scope: local
bookworm: resolved (fixed in 2.7.1-1+deb12u1)
bullseye: resolved (fixed in 2.5.1-1+deb11u2)
forky: resolved (fixed in 2.7.2-1)
sid: resolved (fixed in 2.7.2-1)
trixie: resolved (fixed in 2.7.2-1)
GHSA
GHSA-5f9q-hg2v-3887: A flaw was found in the Libreoffice package
ghsa_unreviewed·2023-07-10
CVE-2023-1183 [MEDIUM] CWE-20 GHSA-5f9q-hg2v-3887: A flaw was found in the Libreoffice package
A flaw was found in the Libreoffice package. An attacker can craft an odb containing a "database/script" file with a SCRIPT command where the contents of the file could be written to a new file whose location was determined by the attacker.
OSV
CVE-2023-1183: A flaw was found in the Libreoffice package
osv·2023-07-10·CVSS 5.5
CVE-2023-1183 [MEDIUM] CVE-2023-1183: A flaw was found in the Libreoffice package
A flaw was found in the Libreoffice package. An attacker can craft an odb containing a "database/script" file with a SCRIPT command where the contents of the file could be written to a new file whose location was determined by the attacker.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.openwall.com/lists/oss-security/2023/12/28/4http://www.openwall.com/lists/oss-security/2024/01/03/4https://access.redhat.com/security/cve/CVE-2023-1183https://bugzilla.redhat.com/show_bug.cgi?id=2208506https://www.libreoffice.org/about-us/security/advisories/cve-2023-1183/http://www.openwall.com/lists/oss-security/2023/12/28/4http://www.openwall.com/lists/oss-security/2024/01/03/4https://access.redhat.com/security/cve/CVE-2023-1183https://bugzilla.redhat.com/show_bug.cgi?id=2208506https://www.libreoffice.org/about-us/security/advisories/cve-2023-1183/
2023-07-10
Published