Improper Preservation of Permissions Affecting libreoffice-help-fr package, versions <1:6.4.7.2-16.0.1.el8_9
Threat Intelligence
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-ORACLE8-LIBREOFFICEHELPFR-6514248
- published 30 Mar 2024
- disclosed 11 Dec 2023
Introduced: 11 Dec 2023
CVE-2023-6186 Open this link in a new tabHow to fix?
Upgrade Oracle:8 libreoffice-help-fr to version 1:6.4.7.2-16.0.1.el8_9 or higher.
This issue was patched in ELSA-2024-1514.
NVD Description
Note: Versions mentioned in the description apply only to the upstream libreoffice-help-fr package and not the libreoffice-help-fr package as distributed by Oracle.
See How to fix? for Oracle:8 relevant fixed versions and status.
Insufficient macro permission validation of The Document Foundation LibreOffice allows an attacker to execute built-in macros without warning.
In affected versions LibreOffice supports hyperlinks with macro or similar built-in command targets that can be executed when activated without warning the user.
References
- https://linux.oracle.com/cve/CVE-2023-6186.html
- https://linux.oracle.com/errata/ELSA-2024-1427.html
- https://linux.oracle.com/errata/ELSA-2024-3835.html
- https://www.libreoffice.org/about-us/security/advisories/cve-2023-6186
- https://www.debian.org/security/2023/dsa-5574
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/QB7UB6CTWQUDOE657OVVRSDYUY3IPBJG/
- https://lists.debian.org/debian-lts-announce/2023/12/msg00026.html