4.3
CVSSv3

CVE-2019-9849

Published: 17/07/2019 Updated: 07/11/2023
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
CVSS v3 Base Score: 4.3 | Impact Score: 1.4 | Exploitability Score: 2.8
VMScore: 356
Vector: AV:N/AC:L/Au:S/C:P/I:N/A:N

Vulnerability Summary

LibreOffice has a 'stealth mode' in which only documents from locations deemed 'trusted' are allowed to retrieve remote resources. This mode is not the default mode, but can be enabled by users who want to disable LibreOffice's ability to include remote resources within a document. A flaw existed where bullet graphics were omitted from this protection prior to version 6.2.5. This issue affects: Document Foundation LibreOffice versions before 6.2.5.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

libreoffice libreoffice

canonical ubuntu linux 16.04

canonical ubuntu linux 18.04

canonical ubuntu linux 19.04

fedoraproject fedora 29

fedoraproject fedora 30

debian debian linux 8.0

opensuse leap 15.0

opensuse leap 15.1

Vendor Advisories

Several security issues were fixed in LibreOffice ...
Two security issues have been discovered in LibreOffice: CVE-2019-9848 Nils Emmerich discovered that malicious documents could execute arbitrary Python code via LibreLogo CVE-2019-9849 Matei Badanoiu discovered that the stealth mode did not apply to bullet graphics For the oldstable distribution (stretch), these problems have be ...
LibreOffice has a feature where documents can specify that pre-installed scripts can be executed on various document events such as mouse-over, etc LibreOffice is typically also bundled with LibreLogo, a programmable turtle vector graphics script, which can be manipulated into executing arbitrary python commands By using the document event featur ...
Impact: Low Public Date: 2019-08-05 CWE: CWE-200 Bugzilla: 1737421: CVE-2019-9849 libreoffice: remote r ...
LibreOffice has a 'stealth mode' in which only documents from locations deemed 'trusted' are allowed to retrieve remote resources This mode is not the default mode, but can be enabled by users who want to disable LibreOffice's ability to include remote resources within a document A flaw existed where bullet graphics were omitted from this protect ...