Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-6186

Опубликовано: 11 дек. 2023
Источник: redhat
CVSS3: 8.3
EPSS Низкий

Описание

Insufficient macro permission validation of The Document Foundation LibreOffice allows an attacker to execute built-in macros without warning. In affected versions LibreOffice supports hyperlinks with macro or similar built-in command targets that can be executed when activated without warning the user.

An insufficient permission validation vulnerability was found in LibreOffice. In versions that support running commands in hyperlinks, an attacker can execute built-in macros without warning the user.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6libreofficeOut of support scope
Red Hat Enterprise Linux 7libreofficeWill not fix
Red Hat Enterprise Linux 8libreoffice:flatpak/libreofficeNot affected
Red Hat Enterprise Linux 9libreoffice:flatpak/libreofficeNot affected
Red Hat Enterprise Linux 8libreofficeFixedRHSA-2024:151426.03.2024
Red Hat Enterprise Linux 8.2 Advanced Update SupportlibreofficeFixedRHSA-2024:151226.03.2024
Red Hat Enterprise Linux 8.2 Telecommunications Update ServicelibreofficeFixedRHSA-2024:151226.03.2024
Red Hat Enterprise Linux 8.2 Update Services for SAP SolutionslibreofficeFixedRHSA-2024:151226.03.2024
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update SupportlibreofficeFixedRHSA-2024:148025.03.2024
Red Hat Enterprise Linux 8.4 Telecommunications Update ServicelibreofficeFixedRHSA-2024:148025.03.2024

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-250
https://bugzilla.redhat.com/show_bug.cgi?id=2254005libreoffice: Insufficient macro permission validation leading to macro execution

EPSS

Процентиль: 78%
0.01179
Низкий

8.3 High

CVSS3

Связанные уязвимости

CVSS3: 8.3
ubuntu
больше 1 года назад

Insufficient macro permission validation of The Document Foundation LibreOffice allows an attacker to execute built-in macros without warning. In affected versions LibreOffice supports hyperlinks with macro or similar built-in command targets that can be executed when activated without warning the user.

CVSS3: 8.3
nvd
больше 1 года назад

Insufficient macro permission validation of The Document Foundation LibreOffice allows an attacker to execute built-in macros without warning. In affected versions LibreOffice supports hyperlinks with macro or similar built-in command targets that can be executed when activated without warning the user.

CVSS3: 8.3
debian
больше 1 года назад

Insufficient macro permission validation of The Document Foundation Li ...

CVSS3: 8.3
github
больше 1 года назад

Insufficient macro permission validation of The Document Foundation LibreOffice allows an attacker to execute built-in macros without warning. In affected versions LibreOffice supports hyperlinks with macro or similar built-in command targets that can be executed when activated without warning the user.

CVSS3: 8.3
fstec
больше 1 года назад

Уязвимость пакета офисных программ LibreOffice, связанная с возможностью внедрения кода или данных, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 78%
0.01179
Низкий

8.3 High

CVSS3