Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-6186

Опубликовано: 11 дек. 2023
Источник: redhat
CVSS3: 8.3

Описание

Insufficient macro permission validation of The Document Foundation LibreOffice allows an attacker to execute built-in macros without warning. In affected versions LibreOffice supports hyperlinks with macro or similar built-in command targets that can be executed when activated without warning the user.

An insufficient permission validation vulnerability was found in LibreOffice. In versions that support running commands in hyperlinks, an attacker can execute built-in macros without warning the user.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6libreofficeOut of support scope
Red Hat Enterprise Linux 7libreofficeWill not fix
Red Hat Enterprise Linux 8libreoffice:flatpak/libreofficeNot affected
Red Hat Enterprise Linux 9libreoffice:flatpak/libreofficeNot affected
Red Hat Enterprise Linux 8libreofficeFixedRHSA-2024:151426.03.2024
Red Hat Enterprise Linux 8.2 Advanced Update SupportlibreofficeFixedRHSA-2024:151226.03.2024
Red Hat Enterprise Linux 8.2 Telecommunications Update ServicelibreofficeFixedRHSA-2024:151226.03.2024
Red Hat Enterprise Linux 8.2 Update Services for SAP SolutionslibreofficeFixedRHSA-2024:151226.03.2024
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update SupportlibreofficeFixedRHSA-2024:148025.03.2024
Red Hat Enterprise Linux 8.4 Telecommunications Update ServicelibreofficeFixedRHSA-2024:148025.03.2024

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-250
https://bugzilla.redhat.com/show_bug.cgi?id=2254005libreoffice: Insufficient macro permission validation leading to macro execution

8.3 High

CVSS3

Связанные уязвимости

CVSS3: 8.3
ubuntu
почти 2 года назад

Insufficient macro permission validation of The Document Foundation LibreOffice allows an attacker to execute built-in macros without warning. In affected versions LibreOffice supports hyperlinks with macro or similar built-in command targets that can be executed when activated without warning the user.

CVSS3: 8.3
nvd
почти 2 года назад

Insufficient macro permission validation of The Document Foundation LibreOffice allows an attacker to execute built-in macros without warning. In affected versions LibreOffice supports hyperlinks with macro or similar built-in command targets that can be executed when activated without warning the user.

CVSS3: 8.3
debian
почти 2 года назад

Insufficient macro permission validation of The Document Foundation Li ...

CVSS3: 8.3
github
почти 2 года назад

Insufficient macro permission validation of The Document Foundation LibreOffice allows an attacker to execute built-in macros without warning. In affected versions LibreOffice supports hyperlinks with macro or similar built-in command targets that can be executed when activated without warning the user.

CVSS3: 8.3
fstec
почти 2 года назад

Уязвимость пакета офисных программ LibreOffice, связанная с возможностью внедрения кода или данных, позволяющая нарушителю выполнить произвольный код

8.3 High

CVSS3