AI analysis
LibreOffice Calc can save a link from a cell range to an external data source inside a spreadsheet. A crafted document can name a Java database driver to be loaded from a remote location, so opening the file can run Java code from that location (CWE-829). An attacker needs a user to open the document and then can affect confidentiality, integrity, and availability of that user's system; no prior privileges on the target are required. Users of unfixed LibreOffice Calc builds that load Java database drivers are affected. There is no known public proof of concept, and the issue is not in CISA's Known Exploited Vulnerabilities catalog.
What to do: Install a fixed LibreOffice release in which a Java classpath entry must be a file URL, and do not open Calc documents from untrusted sources. Until you can update, avoid using external data-source links or Java database drivers in spreadsheets you did not create.
Affected
| The Document Foundation LibreOffice Calc | — |
Estimated exposure
massTens of millions of LibreOffice installations (order-of-magnitude estimate) — Estimate from LibreOffice's publicly reported download and user base, which is well above one million users; this is not a count of confirmed vulnerable or internet-exposed systems, and exploitation still requires a user to open a crafted…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
LibreOffice Calc can link a cell range to an external data source, and the link is saved in the document. A document could name a Java database driver for such a link to be loaded from a remote location, so opening the document could run Java code from that location. In fixed versions an entry in a Java class path has to be a file URL.