Channel and Path Errors Affecting libreoffice-l10n-he package, versions <6.2.7.1-8.10.1


Severity

Recommended
0.0
critical
0
10

Based on SUSE Linux Enterprise Server security rating.

Threat Intelligence

EPSS
0.37% (73rd percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-SLES151-LIBREOFFICEL10NHE-2743461
  • published14 Apr 2022
  • disclosed18 Sept 2019

Introduced: 18 Sep 2019

CVE-2019-9855  (opens in a new tab)
CWE-417  (opens in a new tab)

How to fix?

Upgrade SLES:15.1 libreoffice-l10n-he to version 6.2.7.1-8.10.1 or higher.

NVD Description

Note: Versions mentioned in the description apply only to the upstream libreoffice-l10n-he package and not the libreoffice-l10n-he package as distributed by SLES. See How to fix? for SLES:15.1 relevant fixed versions and status.

LibreOffice is typically bundled with LibreLogo, a programmable turtle vector graphics script, which can execute arbitrary python commands contained with the document it is launched from. LibreOffice also has a feature where documents can specify that pre-installed scripts can be executed on various document script events such as mouse-over, etc. Protection was added to block calling LibreLogo from script event handers. However a Windows 8.3 path equivalence handling flaw left LibreOffice vulnerable under Windows that a document could trigger executing LibreLogo via a Windows filename pseudonym. This issue affects: Document Foundation LibreOffice 6.2 versions prior to 6.2.7; 6.3 versions prior to 6.3.1.

CVSS Scores

version 3.1