CVE-2015-4551
LibreOffice before 4.4.5 and Apache OpenOffice before 4.1.2 uses the stored LinkUpdateMode configuration information in OpenDocument Format files and templates when handling links, which might allow remote attackers to obtain sensitive information via a…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 13.8%, higher than 96% of all known CVEs. Patch or mitigate before the next change window.
Description
LibreOffice before 4.4.5 and Apache OpenOffice before 4.1.2 uses the stored LinkUpdateMode configuration information in OpenDocument Format files and templates when handling links, which might allow remote attackers to obtain sensitive information via a crafted document, which embeds data from local files into (1) Calc or (2) Writer.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
- EPSS
- 13.83% probability · 96th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- libreoffice/libreoffice · canonical/ubuntu linux · debian/debian linux · apache/openoffice
- Source
- cve@mitre.org
References
- http://rhn.redhat.com/errata/RHSA-2015-2619.htmlThird Party Advisory
- http://www.debian.org/security/2015/dsa-3394Third Party Advisory
- http://www.libreoffice.org/about-us/security/advisories/cve-2015-4551/Vendor Advisory
- http://www.openoffice.org/security/cves/CVE-2015-4551.htmlVendor Advisory
- http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.htmlThird Party Advisory
- http://www.securityfocus.com/bid/77486Broken Link, Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1034085Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1034091Third Party Advisory, VDB Entry
- http://www.ubuntu.com/usn/USN-2793-1Third Party Advisory
- https://security.gentoo.org/glsa/201603-05Third Party Advisory
- https://security.gentoo.org/glsa/201611-03Third Party Advisory
- http://rhn.redhat.com/errata/RHSA-2015-2619.htmlThird Party Advisory
- http://www.debian.org/security/2015/dsa-3394Third Party Advisory
- http://www.libreoffice.org/about-us/security/advisories/cve-2015-4551/Vendor Advisory
- http://www.openoffice.org/security/cves/CVE-2015-4551.htmlVendor Advisory
- http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.htmlThird Party Advisory
- http://www.securityfocus.com/bid/77486Broken Link, Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1034085Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1034091Third Party Advisory, VDB Entry
- http://www.ubuntu.com/usn/USN-2793-1Third Party Advisory
- https://security.gentoo.org/glsa/201603-05Third Party Advisory
- https://security.gentoo.org/glsa/201611-03Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.