NA

CVE-2023-1183

Published: 10/07/2023 Updated: 03/01/2024
CVSS v3 Base Score: 5.5 | Impact Score: 3.6 | Exploitability Score: 1.8
VMScore: 0

Vulnerability Summary

A flaw was found in the Libreoffice package. An attacker can craft an odb containing a "database/script" file with a SCRIPT command where the contents of the file could be written to a new file whose location was determined by the attacker.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

libreoffice libreoffice 7.5.0

libreoffice libreoffice

fedoraproject fedora 38

redhat enterprise linux 8.0

redhat enterprise linux 9.0

Vendor Advisories

Synopsis Moderate: libreoffice security update Type/Severity Security Advisory: Moderate Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for libreoffice is now available for Red Hat Enterprise Linux 9Red Hat Product Security has rated this update as hav ...
Gregor Kopf of Secfault Security GmbH discovered that HSQLDB, a Java SQL database engine, allowed the execution of spurious scripting commands in script and log files Hsqldb supports a SCRIPT keyword which is normally used to record the commands input by the database admin to output such a script In combination with LibreOffice, an attacker cou ...
Gregor Kopf of Secfault Security GmbH discovered that HSQLDB, a Java SQL database engine, allowed the execution of spurious scripting commands in script and log files Hsqldb supports a SCRIPT keyword which is normally used to record the commands input by the database admin to output such a script In combination with LibreOffice, an attacker cou ...
A flaw was found in the Libreoffice package An attacker can craft an odb containing a "database/script" file with a SCRIPT command where the contents of the file could be written to a new file whose location was determined by the attacker (CVE-2023-1183) ...
Description<!---->A flaw was found in the Libreoffice package An attacker can craft an odb containing a "database/script" file with a SCRIPT command where the contents of the file could be written to a new file whose location was determined by the attackerA flaw was found in the Libreoffice package An attacker can craft an odb containing a "data ...

Mailing Lists

<!--X-Body-Begin--> <!--X-User-Header--> oss-sec mailing list archives <!--X-User-Header-End--> <!--X-TopPNI--> By Date By Thread </form> <!--X-TopPNI-End--> <!--X-MsgBody--> <!--X-Subject-Header-Begin--> CVE-2023-1183: Apache OpenOffice: Arbitrary file write in Apache OpenOffice Base <!--X-Subject-Header-End--> <!--X-Head-of-Mes ...