Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-38745

Опубликовано: 24 мар. 2023
Источник: redhat
CVSS3: 7.8

Описание

Apache OpenOffice versions before 4.1.14 may be configured to add an empty entry to the Java class path. This may lead to run arbitrary Java code from the current directory.

A flaw was found in LibreOffice. When an empty Java class path entry is configured, LibreOffice will search for Java classes in the current working directory, allowing malicious Java classes to load when opening a document using the file manager, resulting in arbitrary code execution.

Отчет

To exploit this flaw, an attacker would need to convince a user to extract an archive (tar, zip, etc) containing a LibreOffice document and a specific file with Java code inside it, and then the user would need to open the LibreOffice document normally. As user interaction is required to open an unstrusted file, this flaw was rated with a moderate security impact.

Меры по смягчению последствий

Disabling the Java runtime in LibreOffice will mitigate this issue. To disable it, uncheck the "Use a Java runtime environment" option box via: Tools, Options, LibreOffice/Advanced, Use a Java runtime environment.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6libreofficeOut of support scope
Red Hat Enterprise Linux 7libreofficeOut of support scope
Red Hat Enterprise Linux 8libreoffice:flatpak/libreofficeWill not fix
Red Hat Enterprise Linux 9libreoffice:flatpak/libreofficeWill not fix
Red Hat Enterprise Linux 8libreofficeFixedRHSA-2023:693314.11.2023
Red Hat Enterprise Linux 9libreofficeFixedRHSA-2023:650807.11.2023

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-427
Дефект:
CWE-1188->CWE-94
https://bugzilla.redhat.com/show_bug.cgi?id=2182044libreoffice: Empty entry in Java class path

7.8 High

CVSS3

Связанные уязвимости

CVSS3: 7.8
ubuntu
около 2 лет назад

Apache OpenOffice versions before 4.1.14 may be configured to add an empty entry to the Java class path. This may lead to run arbitrary Java code from the current directory.

CVSS3: 7.8
nvd
около 2 лет назад

Apache OpenOffice versions before 4.1.14 may be configured to add an empty entry to the Java class path. This may lead to run arbitrary Java code from the current directory.

CVSS3: 7.8
debian
около 2 лет назад

Apache OpenOffice versions before 4.1.14 may be configured to add an e ...

CVSS3: 7.8
github
около 2 лет назад

Apache OpenOffice versions before 4.1.14 may be configured to add an empty entry to the Java class path. This may lead to run arbitrary Java code from the current directory.

CVSS3: 8.8
fstec
около 2 лет назад

Уязвимость пакета офисных программ Apache OpenOffice, связанная с возможностью добавления пустой записи в путь к Java-классу, позволяющая нарушителю выполнить произвольный код

7.8 High

CVSS3