Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2022-26306

Опубликовано: 25 июл. 2022
Источник: ubuntu
Приоритет: medium
CVSS3: 7.5

Описание

LibreOffice supports the storage of passwords for web connections in the user’s configuration database. The stored passwords are encrypted with a single master key provided by the user. A flaw in LibreOffice existed where the required initialization vector for encryption was always the same which weakens the security of the encryption making them vulnerable if an attacker has access to the user's configuration data. This issue affects: The Document Foundation LibreOffice 7.2 versions prior to 7.2.7; 7.3 versions prior to 7.3.1.

РелизСтатусПримечание
bionic

released

1:6.0.7-0ubuntu0.18.04.12
devel

not-affected

esm-infra/focal

released

1:6.4.7-0ubuntu0.20.04.5
focal

released

1:6.4.7-0ubuntu0.20.04.5
jammy

not-affected

1:7.3.3-0ubuntu0.22.04.1
kinetic

not-affected

lunar

not-affected

trusty

ignored

end of standard support
upstream

released

1:7.3.3~rc1-2
xenial

ignored

end of standard support

Показывать по

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
redhat
больше 3 лет назад

LibreOffice supports the storage of passwords for web connections in the user’s configuration database. The stored passwords are encrypted with a single master key provided by the user. A flaw in LibreOffice existed where the required initialization vector for encryption was always the same which weakens the security of the encryption making them vulnerable if an attacker has access to the user's configuration data. This issue affects: The Document Foundation LibreOffice 7.2 versions prior to 7.2.7; 7.3 versions prior to 7.3.1.

CVSS3: 7.5
nvd
больше 3 лет назад

LibreOffice supports the storage of passwords for web connections in the user’s configuration database. The stored passwords are encrypted with a single master key provided by the user. A flaw in LibreOffice existed where the required initialization vector for encryption was always the same which weakens the security of the encryption making them vulnerable if an attacker has access to the user's configuration data. This issue affects: The Document Foundation LibreOffice 7.2 versions prior to 7.2.7; 7.3 versions prior to 7.3.1.

CVSS3: 7.5
debian
больше 3 лет назад

LibreOffice supports the storage of passwords for web connections in t ...

CVSS3: 7.5
github
больше 3 лет назад

LibreOffice supports the storage of passwords for web connections in the user’s configuration database. The stored passwords are encrypted with a single master key provided by the user. A flaw in LibreOffice existed where the required initialization vector for encryption was always the same which weakens the security of the encryption making them vulnerable if an attacker has access to the user's configuration data. This issue affects: The Document Foundation LibreOffice 7.2 versions prior to 7.2.7; 7.3 versions prior to 7.3.1.

CVSS3: 7.5
fstec
больше 3 лет назад

Уязвимость базы данных конфигураций пользователя пакета офисных программ LibreOffice, позволяющая нарушителю раскрыть защищаемую информацию

7.5 High

CVSS3