Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-v39m-j232-p3qr

Опубликовано: 14 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

It was found that libreoffice before versions 6.0.7 and 6.1.3 was vulnerable to a directory traversal attack which could be used to execute arbitrary macros bundled with a document. An attacker could craft a document, which when opened by LibreOffice, would execute a Python method from a script in any arbitrary file system location, specified relative to the LibreOffice install location.

It was found that libreoffice before versions 6.0.7 and 6.1.3 was vulnerable to a directory traversal attack which could be used to execute arbitrary macros bundled with a document. An attacker could craft a document, which when opened by LibreOffice, would execute a Python method from a script in any arbitrary file system location, specified relative to the LibreOffice install location.

EPSS

Процентиль: 100%
0.92343
Критический

9.8 Critical

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 7.8
ubuntu
почти 7 лет назад

It was found that libreoffice before versions 6.0.7 and 6.1.3 was vulnerable to a directory traversal attack which could be used to execute arbitrary macros bundled with a document. An attacker could craft a document, which when opened by LibreOffice, would execute a Python method from a script in any arbitrary file system location, specified relative to the LibreOffice install location.

CVSS3: 7.8
redhat
около 7 лет назад

It was found that libreoffice before versions 6.0.7 and 6.1.3 was vulnerable to a directory traversal attack which could be used to execute arbitrary macros bundled with a document. An attacker could craft a document, which when opened by LibreOffice, would execute a Python method from a script in any arbitrary file system location, specified relative to the LibreOffice install location.

CVSS3: 7.8
nvd
почти 7 лет назад

It was found that libreoffice before versions 6.0.7 and 6.1.3 was vulnerable to a directory traversal attack which could be used to execute arbitrary macros bundled with a document. An attacker could craft a document, which when opened by LibreOffice, would execute a Python method from a script in any arbitrary file system location, specified relative to the LibreOffice install location.

CVSS3: 7.8
debian
почти 7 лет назад

It was found that libreoffice before versions 6.0.7 and 6.1.3 was vuln ...

suse-cvrf
больше 6 лет назад

Security update for LibreOffice

EPSS

Процентиль: 100%
0.92343
Критический

9.8 Critical

CVSS3

Дефекты

CWE-22