Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2021-25631

Опубликовано: 03 мая 2021
Источник: debian
EPSS Низкий

Описание

In the LibreOffice 7-1 series in versions prior to 7.1.2, and in the 7-0 series in versions prior to 7.0.5, the denylist can be circumvented by manipulating the link so it doesn't match the denylist but results in ShellExecute attempting to launch an executable type.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
libreofficenot-affectedpackage

Примечания

  • https://positive.security/blog/url-open-rce#open-libreoffice

EPSS

Процентиль: 89%
0.0428
Низкий

Связанные уязвимости

CVSS3: 8.8
ubuntu
почти 5 лет назад

In the LibreOffice 7-1 series in versions prior to 7.1.2, and in the 7-0 series in versions prior to 7.0.5, the denylist can be circumvented by manipulating the link so it doesn't match the denylist but results in ShellExecute attempting to launch an executable type.

CVSS3: 8.8
nvd
почти 5 лет назад

In the LibreOffice 7-1 series in versions prior to 7.1.2, and in the 7-0 series in versions prior to 7.0.5, the denylist can be circumvented by manipulating the link so it doesn't match the denylist but results in ShellExecute attempting to launch an executable type.

github
больше 3 лет назад

In the LibreOffice 7-1 series in versions prior to 7.1.2, and in the 7-0 series in versions prior to 7.0.5, the denylist can be circumvented by manipulating the link so it doesn't match the denylist but results in ShellExecute attempting to launch an executable type.

CVSS3: 8.8
fstec
почти 5 лет назад

Уязвимость пакета офисных программ LibreOffice, связанная с ошибками в настройках безопасности, позволяющая нарушителю оказать воздействие на конфиденциальность, целостность и доступность защищаемой информации

EPSS

Процентиль: 89%
0.0428
Низкий