NA

CVE-2022-3140

Published: 11/10/2022 Updated: 27/03/2023
CVSS v3 Base Score: 6.3 | Impact Score: 3.4 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

LibreOffice supports Office URI Schemes to enable browser integration of LibreOffice with MS SharePoint server. An additional scheme 'vnd.libreoffice.command' specific to LibreOffice was added. In the affected versions of LibreOffice links using that scheme could be constructed to call internal macros with arbitrary arguments. Which when clicked on, or activated by document events, could result in arbitrary script execution without warning. This issue affects: The Document Foundation LibreOffice 7.4 versions before 7.4.1; 7.3 versions before 7.3.6.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

libreoffice libreoffice 7.4.0

libreoffice libreoffice

debian debian linux 11.0

fedoraproject fedora 35

Vendor Advisories

Several security issues were fixed in LibreOffice ...
Synopsis Moderate: libreoffice security update Type/Severity Security Advisory: Moderate Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for libreoffice is now available for Red Hat Enterprise Linux 9Red Hat Product Security has rated this update as hav ...
Synopsis Moderate: libreoffice security update Type/Severity Security Advisory: Moderate Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for libreoffice is now available for Red Hat Enterprise Linux 8Red Hat Product Security has rated this update as hav ...
It was discovered that insufficient validation of vndlibreofficecommand URI schemes could result in the execution of arbitrary macro commands For the stable distribution (bullseye), this problem has been fixed in version 1:704-4+deb11u4 We recommend that you upgrade your libreoffice packages For the detailed security status of libreoffice pl ...
DescriptionThe MITRE CVE dictionary describes this issue as: LibreOffice supports Office URI Schemes to enable browser integration of LibreOffice with MS SharePoint server An additional scheme 'vndlibreofficecommand' specific to LibreOffice was added In the affected versions of LibreOffice links using that scheme could be constructed to call in ...
links using that scheme could be constructed to call internal macros with arbitrary arguments Which when clicked on, or activated by document events, could result in arbitrary script execution without warning ...