Channel and Path Errors Affecting libreoffice package, versions <6.3.1.2-r0


Severity

Recommended
0.0
critical
0
10

Snyk's Security Team recommends NVD's CVSS assessment. Learn more

Threat Intelligence

EPSS
0.37% (73rd percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-ALPINE320-LIBREOFFICE-7012765
  • published23 May 2024
  • disclosed6 Sept 2019

Introduced: 6 Sep 2019

CVE-2019-9855  (opens in a new tab)
CWE-417  (opens in a new tab)

How to fix?

Upgrade Alpine:3.20 libreoffice to version 6.3.1.2-r0 or higher.

NVD Description

Note: Versions mentioned in the description apply only to the upstream libreoffice package and not the libreoffice package as distributed by Alpine. See How to fix? for Alpine:3.20 relevant fixed versions and status.

LibreOffice is typically bundled with LibreLogo, a programmable turtle vector graphics script, which can execute arbitrary python commands contained with the document it is launched from. LibreOffice also has a feature where documents can specify that pre-installed scripts can be executed on various document script events such as mouse-over, etc. Protection was added to block calling LibreLogo from script event handers. However a Windows 8.3 path equivalence handling flaw left LibreOffice vulnerable under Windows that a document could trigger executing LibreLogo via a Windows filename pseudonym. This issue affects: Document Foundation LibreOffice 6.2 versions prior to 6.2.7; 6.3 versions prior to 6.3.1.

CVSS Scores

version 3.1