Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-3044

Опубликовано: 14 мая 2024
Источник: redhat
CVSS3: 7.3
EPSS Низкий

Описание

Unchecked script execution in Graphic on-click binding in affected LibreOffice versions allows an attacker to create a document which without prompt will execute scripts built-into LibreOffice on clicking a graphic. Such scripts were previously deemed trusted but are now deemed untrusted.

A flaw was found in LibreOffice. Unchecked script execution in graphic on-click binding allows an attacker to create a document, which, without a prompt, will execute scripts built into LibreOffice when clicking a graphic. These scripts were previously deemed trusted but are now deemed untrusted.

Отчет

CVE-2024-3044 poses a Moderate severity risk due to its potential to enable unauthorized script execution within LibreOffice documents. While the vulnerability allows for the execution of untrusted scripts upon clicking graphics, it requires user interaction to initiate. Furthermore, the impact is constrained by the user's explicit macro execution permissions, determined at document load time. Although the flaw could lead to unintended script execution, its impact is mitigated by the necessity for user interaction and the reliance on explicit macro permissions.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6libreofficeOut of support scope
Red Hat Enterprise Linux 7libreofficeOut of support scope
Red Hat Enterprise Linux 8libreoffice:flatpak/libreofficeWill not fix
Red Hat Enterprise Linux 9libreoffice:flatpak/libreofficeWill not fix
Red Hat Enterprise Linux 8libreofficeFixedRHSA-2024:424202.07.2024
Red Hat Enterprise Linux 9libreofficeFixedRHSA-2024:475523.07.2024

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-20
https://bugzilla.redhat.com/show_bug.cgi?id=2280542libreoffice: create a document which without prompt will execute scripts built-into LibreOffice on clicking a graphic

EPSS

Процентиль: 78%
0.01169
Низкий

7.3 High

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
около 1 года назад

Unchecked script execution in Graphic on-click binding in affected LibreOffice versions allows an attacker to create a document which without prompt will execute scripts built-into LibreOffice on clicking a graphic. Such scripts were previously deemed trusted but are now deemed untrusted.

CVSS3: 6.5
nvd
около 1 года назад

Unchecked script execution in Graphic on-click binding in affected LibreOffice versions allows an attacker to create a document which without prompt will execute scripts built-into LibreOffice on clicking a graphic. Such scripts were previously deemed trusted but are now deemed untrusted.

CVSS3: 6.5
debian
около 1 года назад

Unchecked script execution in Graphic on-click binding in affected Lib ...

suse-cvrf
12 месяцев назад

Security update for libreoffice

suse-cvrf
12 месяцев назад

Security update for libreoffice

EPSS

Процентиль: 78%
0.01169
Низкий

7.3 High

CVSS3