7.5
CVSSv2

CVE-2019-9848

Published: 17/07/2019 Updated: 07/11/2023
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 791
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

LibreOffice has a feature where documents can specify that pre-installed scripts can be executed on various document events such as mouse-over, etc. LibreOffice is typically also bundled with LibreLogo, a programmable turtle vector graphics script, which can be manipulated into executing arbitrary python commands. By using the document event feature to trigger LibreLogo to execute python contained within a document a malicious document could be constructed which would execute arbitrary python commands silently without warning. In the fixed versions, LibreLogo cannot be called from a document event handler. This issue affects: Document Foundation LibreOffice versions before 6.2.5.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

libreoffice libreoffice

canonical ubuntu linux 16.04

canonical ubuntu linux 18.04

canonical ubuntu linux 19.04

fedoraproject fedora 29

fedoraproject fedora 30

debian debian linux 8.0

opensuse leap 15.0

opensuse leap 15.1

Vendor Advisories

Several security issues were fixed in LibreOffice ...
Two security issues have been discovered in LibreOffice: CVE-2019-9848 Nils Emmerich discovered that malicious documents could execute arbitrary Python code via LibreLogo CVE-2019-9849 Matei Badanoiu discovered that the stealth mode did not apply to bullet graphics For the oldstable distribution (stretch), these problems have be ...
It was discovered that the code fixes to address CVE-2018-16858 and CVE-2019-9848 were not complete For the oldstable distribution (stretch), these problems have been fixed in version 1:527-1+deb9u10 For the stable distribution (buster), these problems have been fixed in version 1:615-3+deb10u3 We recommend that you upgrade your libreoffice ...
LibreOffice has a feature where documents can specify that pre-installed scripts can be executed on various document events such as mouse-over, etc LibreOffice is typically also bundled with LibreLogo, a programmable turtle vector graphics script, which can be manipulated into executing arbitrary python commands By using the document event featur ...
Impact: Moderate Public Date: 2019-08-05 CWE: CWE-20 Bugzilla: 1737427: CVE-2019-9848 libreoffice: Libr ...
An issue has been found in LibreOffice before 625, where documents can specify that pre-installed scripts can be executed on various document events such as mouse-over, etc LibreOffice is typically also bundled with LibreLogo, a programmable turtle vector graphics script, which can be manipulated into executing arbitrary python commands By usin ...

Exploits

This Metasploit module generates an ODT file with a dom loaded event that, when triggered, will execute arbitrary python code and the metasploit payload ...

Recent Articles

LibreOffice handlers defend suite's security after 'unfortunately partial' patch
The Register • Tim Anderson • 02 Aug 2019

When is a macro not a macro? When it comes with the product, apparently Fix LibreOffice now to thwart silent macro viruses – and here's how to pwn those who haven't

Interview The Document Foundation, custodian of LibreOffice, has defended the suite's security after attempts to patch a code execution flaw turned out to be "partial". "So far in the story of LibreOffice we have been able to patch all security issues before they reached the end user," a spokesperson told The Reg. "For this last one we have a patch for version 6.2.5 which is unfortunately partial because there are other ways to trigger the vulnerability. This is going to be patched in version 6....

Fix LibreOffice now to thwart silent macro viruses – and here's how to pwn those who haven't
The Register • Tim Anderson • 30 Jul 2019

Remove LibreLogo immediately LibreOffice 6.3 hits beta, with built-in redaction tool for sharing those █████ documents

Updated See our note below: LibreOffice version 6.2.5, which was supposed to patch the macro security hole, is still vulnerable, and exploit code is now available. Disable LibreLogo immediately if it is present and enabled in your build of LibreOffice. Our amended article follows. The Document Foundation said on Tuesday that it had recently patched LibreOffice, its open-source office suite, to fix* an issue where documents can be configured to run macros silently on opening. The code execution v...

Fix LibreOffice now to thwart silent macro viruses – and here's how to pwn those who haven't
The Register • Tim Anderson • 30 Jul 2019

Remove LibreLogo immediately LibreOffice 6.3 hits beta, with built-in redaction tool for sharing those █████ documents

Updated See our note below: LibreOffice version 6.2.5, which was supposed to patch the macro security hole, is still vulnerable, and exploit code is now available. Disable LibreLogo immediately if it is present and enabled in your build of LibreOffice. Our amended article follows. The Document Foundation said on Tuesday that it had recently patched LibreOffice, its open-source office suite, to fix* an issue where documents can be configured to run macros silently on opening. The code execution v...