NA

CVE-2022-26307

Published: 25/07/2022 Updated: 11/07/2023
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

LibreOffice supports the storage of passwords for web connections in the user’s configuration database. The stored passwords are encrypted with a single master key provided by the user. A flaw in LibreOffice existed where master key was poorly encoded resulting in weakening its entropy from 128 to 43 bits making the stored passwords vulerable to a brute force attack if an attacker has access to the users stored config. This issue affects: The Document Foundation LibreOffice 7.2 versions before 7.2.7; 7.3 versions before 7.3.3.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

libreoffice libreoffice

debian debian linux 10.0

Vendor Advisories

Synopsis Moderate: libreoffice security update Type/Severity Security Advisory: Moderate Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for libreoffice is now available for Red Hat Enterprise Linux 9Red Hat Product Security has rated this update as hav ...
Synopsis Moderate: libreoffice security update Type/Severity Security Advisory: Moderate Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for libreoffice is now available for Red Hat Enterprise Linux 8Red Hat Product Security has rated this update as hav ...
Several security issues were fixed in LibreOffice ...
Several security issues were fixed in LibreOffice ...
LibreOffice supports the storage of passwords for web connections in the user’s configuration database The stored passwords are encrypted with a single master key provided by the user A flaw in LibreOffice existed where master key was poorly encoded resulting in weakening its entropy from 128 to 43 bits making the stored passwords vuler ...
Severity Unknown Remote Unknown Type Unknown Description AVG-2784 libreoffice-still 726-3 727-1 Unknown Fixed AVG-2783 libreoffice-fresh 732-2 733-1 Unknown ...