cbcvebase.
CVE-2023-1183
published 2023-07-10

CVE-2023-1183: A flaw was found in the Libreoffice package. An attacker can craft an odb containing a "database/script" file with a SCRIPT command where the contents of the…

PriorityP344medium5.5CVSS 3.1
AVLACLPRNUIRSUCNIHAN
EPSS
64.63%
99.2th percentile
A flaw was found in the Libreoffice package. An attacker can craft an odb containing a "database/script" file with a SCRIPT command where the contents of the file could be written to a new file whose location was determined by the attacker.

Affected

7 ranges
VendorProductVersion rangeFixed in
debianhsqldb< hsqldb 2.7.1-1+deb12u1 (bookworm)hsqldb 2.7.1-1+deb12u1 (bookworm)
debianhsqldb1.8.0< hsqldb 2.7.1-1+deb12u1 (bookworm)hsqldb 2.7.1-1+deb12u1 (bookworm)
fedoraprojectfedora
libreofficelibreoffice< 7.4.67.4.6
libreofficelibreoffice
redhatenterprise_linux
redhatenterprise_linux

Detection & IOCsextracted from sources · hover to see the quote

  • Malicious .odb file containing a crafted 'database/script' file with a SCRIPT command used to achieve arbitrary file write
  • Inspect .odb archives (ZIP format) for the presence of a 'database/script' entry containing SCRIPT commands, which is anomalous and indicative of exploitation attempts
  • ·Vulnerability is local scope only; attacker must deliver and have the victim open a malicious .odb file
  • ·Red Hat Enterprise Linux 6 is out of support scope and RHEL 7 will not receive a fix; patched versions are available for Debian (bookworm: 2.7.1-1+deb12u1, bullseye: 2.5.1-1+deb11u2) and Debian sid/trixie/forky (2.7.2-1)

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
osv5.5MEDIUM
vendor_redhat5.5MEDIUM
vendor_debian5.0MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.