CVE-2019-9851
LibreOffice is typically bundled with LibreLogo, a programmable turtle vector graphics script, which can execute arbitrary python commands contained with the document it is launched from.
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 78.3%, higher than 100% of all known CVEs. Patch or mitigate before the next change window.
Description
LibreOffice is typically bundled with LibreLogo, a programmable turtle vector graphics script, which can execute arbitrary python commands contained with the document it is launched from. Protection was added, to address CVE-2019-9848, to block calling LibreLogo from document event script handers, e.g. mouse over. However LibreOffice also has a separate feature where documents can specify that pre-installed scripts can be executed on various global script events such as document-open, etc. In the fixed versions, global script event handlers are validated equivalently to document script event handlers. This issue affects: Document Foundation LibreOffice versions prior to 6.2.6.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 78.35% probability · 100th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- canonical/ubuntu linux · debian/debian linux · fedoraproject/fedora · opensuse/leap · libreoffice/libreoffice
- Source
- security@documentfoundation.org
References
- http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00006.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00067.htmlMailing List, Third Party Advisory
- http://packetstormsecurity.com/files/154168/LibreOffice-Macro-Python-Code-Execution.htmlThird Party Advisory, VDB Entry
- https://lists.debian.org/debian-lts-announce/2019/10/msg00005.htmlMailing List, Third Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PMEGUWMWORC3DOVEHVXLFT3A5RSCMLBH/
- https://seclists.org/bugtraq/2019/Aug/28Mailing List, Third Party Advisory
- https://usn.ubuntu.com/4102-1/Third Party Advisory
- https://www.debian.org/security/2019/dsa-4501Third Party Advisory
- https://www.libreoffice.org/about-us/security/advisories/CVE-2019-9851Vendor Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00006.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00067.htmlMailing List, Third Party Advisory
- http://packetstormsecurity.com/files/154168/LibreOffice-Macro-Python-Code-Execution.htmlThird Party Advisory, VDB Entry
- https://lists.debian.org/debian-lts-announce/2019/10/msg00005.htmlMailing List, Third Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PMEGUWMWORC3DOVEHVXLFT3A5RSCMLBH/
- https://seclists.org/bugtraq/2019/Aug/28Mailing List, Third Party Advisory
- https://usn.ubuntu.com/4102-1/Third Party Advisory
- https://www.debian.org/security/2019/dsa-4501Third Party Advisory
- https://www.libreoffice.org/about-us/security/advisories/CVE-2019-9851Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.