ZeroHour
Security Affairspublished ()ingested @securityaffairs

Hurry Up! Update your LibreOffice because 2 patches have been bypassed

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2018-16858
It was found that libreoffice before versions 6.0.7 and 6.1.3 was vulnerable to a directory traversal attack which could be used to execute arbitrary macros bun

It was found that libreoffice before versions 6.0.7 and 6.1.3 was vulnerable to a directory traversal attack which could be used to execute arbitrary macros bundled with a document. An attacker could craft a document, which when opened by LibreOffice, would execute a Python method from a script in any arbitrary file system location, specified relative to the LibreOffice install location.

NVD description · AI analysis pending
9.867% PoC ×2
  • libreoffice libreoffice
CVE-2019-9848
+1 in the same advisory: …9849
LibreOffice has a feature where documents can specify that pre-installed scripts can be executed on various document events such as mouse-over, etc.

LibreOffice has a feature where documents can specify that pre-installed scripts can be executed on various document events such as mouse-over, etc. LibreOffice is typically also bundled with LibreLogo, a programmable turtle vector graphics script, which can be manipulated into executing arbitrary python commands. By using the document event feature to trigger LibreLogo to execute python contained within a document a malicious document could be constructed which would execute arbitrary python commands silently without warning. In the fixed versions, LibreLogo cannot be called from a document event handler. This issue affects: Document Foundation LibreOffice versions prior to 6.2.5.

NVD description · AI analysis pending
9.8
group max
31%
  • libreoffice libreoffice
  • libreoffice ubuntu linux
  • libreoffice fedora
  • +1 more
CVE-2019-9851
+2 in the same advisory: …9850 …9852
LibreOffice is typically bundled with LibreLogo, a programmable turtle vector graphics script, which can execute arbitrary python commands contained with the do

LibreOffice is typically bundled with LibreLogo, a programmable turtle vector graphics script, which can execute arbitrary python commands contained with the document it is launched from. Protection was added, to address CVE-2019-9848, to block calling LibreLogo from document event script handers, e.g. mouse over. However LibreOffice also has a separate feature where documents can specify that pre-installed scripts can be executed on various global script events such as document-open, etc. In the fixed versions, global script event handlers are validated equivalently to document script event handlers. This issue affects: Document Foundation LibreOffice versions prior to 6.2.6.

NVD description · AI analysis pending
9.8
group max
78%
  • canonical ubuntu linux
  • canonical debian linux
  • canonical fedora
  • +1 more
Full article400 words · extracted from securityaffairs.com · click to collapse

The latest version of LibreOffice (6.2.6/6.3.0) addresses three vulnerabilities that could be exploited by attackers to bypass patches for two previously addressed issues.

LibreOffice has released a new version of the popular open-source office software that addressed three vulnerabilities that could be exploited by attackers to bypass patches for two previously addressed issues.

LibreOffice attempted to fix one of the flaws, tracked as CVE-2019-9848, last month with the release of the version 6.2.5 that also addressed another issue (CVE-2019-9849).

The flaw resides in LibreLogo, a programmable turtle vector graphics script that ships by default with LibreOffice. LibreLogo allows users to specify pre-installed scripts in a document that can be executed when some events occur.

The flaw can be exploited by attackers using specially crafted malicious LibreOffice document files that can result in the silent execution of arbitrary python commands without displaying any warning to the victim.

The vulnerability was first discovered by security expert Nils Emmerich who explained that using forms and OnFocus event, it is even possible to execute arbitrary code when the document is opened, without the need for a mouse-over event.

Unfortunately, the patch did not completely address the issue, at least two separate security researchers found a way to bypass it and trigger the flaw again by exploiting the following 2 new vulnerabilities:

  • CVE-2019-9850 vulnerability in LibreOffice exists due to insufficient URL validation that allows malicious attackers to bypass the patch initially developed for the CVE-2019-9848 and again trigger calling LibreLogo from script event handlers. The flaw was also discovered by Alex Inführ
  • CVE-2019-9851 vulnerability resides in a separate feature where documents can specify pre-installed scripts, just like LibreLogo, which can be executed on various global script events such as document-open, etc. The vulnerability was discovered by the security researcher Gabriel Masei.

LibreOffice initially patched the CVE-2018-16858 in February, but it has successfully been bypassed by a directory traversal attack that could be exploited by an attacker to execute any script from arbitrary locations on the target’s file system.

  • CVE-2019-9852 URL encoding attack could be exploited by attackers to bypass patch for directory traversal attack.

An attacker can chain the three vulnerabilities to remotely execute malicious commands on a targeted computer by tricking the victim into opening a maliciously-crafted document.

Don’t waste time, update your LibreOffice to the latest version.

[adrotate banner=”9″] [adrotate banner=”12″]

Pierluigi Paganini

(SecurityAffairs – LibreOffice, hacking)

[adrotate banner=”5″]

[adrotate banner=”13″]



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/89962/hacking/libreoffice-flaws.html