4.3
CVSSv2

CVE-2017-3157

Published: 20/11/2017 Updated: 08/05/2019
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 5.5 | Impact Score: 3.6 | Exploitability Score: 1.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N

Vulnerability Summary

By exploiting the way Apache OpenOffice prior to 4.1.4 renders embedded objects, an attacker could craft a document that allows reading in a file from the user's filesystem. Information could be retrieved by the attacker by, e.g., using hidden sections to store the information, tricking the user into saving the document and convincing the user to send the document back to the attacker. The vulnerability is mitigated by the need for the malicious user to know the precise file path in the target system, and the need to trick the user into saving the document and sending it back.

Vulnerable Product Search on Vulmon Subscribe to Product

apache openoffice

debian debian linux 9.0

debian debian linux 8.0

redhat enterprise linux server aus 7.6

redhat enterprise linux server eus 7.3

redhat enterprise linux server eus 7.4

redhat enterprise linux server eus 7.5

redhat enterprise linux server eus 7.6

redhat enterprise linux server tus 7.3

redhat enterprise linux server 7.0

redhat enterprise linux server aus 7.3

redhat enterprise linux server tus 7.6

redhat enterprise linux desktop 6.0

redhat enterprise linux server 6.0

redhat enterprise linux workstation 6.0

redhat enterprise linux desktop 7.0

redhat enterprise linux workstation 7.0

redhat enterprise linux server aus 7.4

Vendor Advisories

LibreOffice could be made to disclose files if it opened a specially crafted file ...
Synopsis Moderate: libreoffice security and bug fix update Type/Severity Security Advisory: Moderate Topic An update for libreoffice is now available for Red Hat Enterprise Linux 7Red Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerability Scoring System ( ...
Synopsis Moderate: libreoffice security update Type/Severity Security Advisory: Moderate Topic An update for libreoffice is now available for Red Hat Enterprise Linux 6Red Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerability Scoring System (CVSS) base s ...
Ben Hayak discovered that objects embedded in Writer and Calc documents may result in information disclosure Please see wwwlibreofficeorg/about-us/security/advisories/cve-2017-3157/ for additional information For the stable distribution (jessie), this problem has been fixed in version 1:433-2+deb8u6 For the testing distribution (str ...
It was found that LibreOffice disclosed contents of a file specified in an embedded object's preview An attacker could potentially use this flaw to expose details of a system running LibreOffice as an online service via a crafted document ...