4.3
CVSSv2

CVE-2015-4551

Published: 10/11/2015 Updated: 07/02/2022
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N

Vulnerability Summary

LibreOffice prior to 4.4.5 and Apache OpenOffice prior to 4.1.2 uses the stored LinkUpdateMode configuration information in OpenDocument Format files and templates when handling links, which might allow remote malicious users to obtain sensitive information via a crafted document, which embeds data from local files into (1) Calc or (2) Writer.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

libreoffice libreoffice

canonical ubuntu linux 15.04

canonical ubuntu linux 12.04

canonical ubuntu linux 14.04

debian debian linux 7.0

debian debian linux 8.0

apache openoffice

Vendor Advisories

Synopsis Moderate: libreoffice security update Type/Severity Security Advisory: Moderate Topic Updated libreoffice packages that fixes multiple security issues are nowavailable for Red Hat Enterprise Linux 6 and 7Red Hat Product Security has rated this update as having Moderate securityimpact Common Vulne ...
Several security issues were fixed in LibreOffice ...
Multiple vulnerabilities have been discovered in LibreOffice, a full-featured office productivity: CVE-2015-4551 Federico Scrinzi discovered an information leak in the handling of ODF documents Quoting from wwwlibreofficeorg/about-us/security/advisories/cve-2015-4551/: The LinkUpdateMode feature controls whether document ...
It was discovered that LibreOffice did not properly restrict automatic link updates By tricking a victim into opening specially crafted documents, an attacker could possibly use this flaw to disclose contents of files accessible by the victim ...