CVE-2019-9850
libreoffice - security update
描述
LibreOffice is typically bundled with LibreLogo, a programmable turtle vector graphics script, which can execute arbitrary python commands contained with the document it is launched from. LibreOffice also has a feature where documents can specify that pre-installed scripts can be executed on various document script events such as mouse-over, etc. Protection was added, to address CVE-2019-9848, to block calling LibreLogo from script event handers. However an insufficient url validation vulnerability in LibreOffice allowed malicious to bypass that protection and again trigger calling LibreLogo from script event handlers. This issue affects: Document Foundation LibreOffice versions prior to 6.2.6.
如何修補 CVE-2019-9850
要修補 CVE-2019-9850,請將受影響套件升級到下列已修補版本。
- —升級至 1:6.3.0-1 或更新版本
- —升級至 1:5.2.7-1+deb9u10 或更新版本
CVE-2019-9850 正在被利用嗎?
低 — EPSS 為 3.4%,目前沒有觀察到大規模利用活動。
受影響套件(2)
- from 0, < 1:6.3.0-1
- from 0, < 1:5.2.7-1+deb9u10
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | CRITICAL9.8 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |