CVE-2019-9849
Summary
| CVE | CVE-2019-9849 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-07-17 12:15:00 UTC |
| Updated | 2023-11-07 03:13:00 UTC |
| Description | LibreOffice has a 'stealth mode' in which only documents from locations deemed 'trusted' are allowed to retrieve remote resources. This mode is not the default mode, but can be enabled by users who want to disable LibreOffice's ability to include remote resources within a document. A flaw existed where bullet graphics were omitted from this protection prior to version 6.2.5. This issue affects: Document Foundation LibreOffice versions prior to 6.2.5. |
Risk And Classification
Problem Types: NVD-CWE-noinfo
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Canonical | Ubuntu Linux | 16.04 | All | All | All |
| Operating System | Canonical | Ubuntu Linux | 18.04 | All | All | All |
| Operating System | Canonical | Ubuntu Linux | 19.04 | All | All | All |
| Operating System | Canonical | Ubuntu Linux | 16.04 | All | All | All |
| Operating System | Canonical | Ubuntu Linux | 18.04 | All | All | All |
| Operating System | Canonical | Ubuntu Linux | 19.04 | All | All | All |
| Operating System | Debian | Debian Linux | 8.0 | All | All | All |
| Operating System | Fedoraproject | Fedora | 29 | All | All | All |
| Operating System | Fedoraproject | Fedora | 30 | All | All | All |
| Operating System | Fedoraproject | Fedora | 30 | All | All | All |
| Application | Libreoffice | Libreoffice | All | All | All | All |
| Application | Libreoffice | Libreoffice | All | All | All | All |
| Operating System | Opensuse | Leap | 15.0 | All | All | All |
| Operating System | Opensuse | Leap | 15.1 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| CVE-2019-9849 | LibreOffice - Free Office Suite - Fun Project - Fantastic People | CONFIRM | www.libreoffice.org | Vendor Advisory |
| LibreOffice: Multiple vulnerabilities (GLSA 201908-13) — Gentoo security | GENTOO | security.gentoo.org | |
| [SECURITY] Fedora 30 Update: libreoffice-6.2.5.2-1.fc30 - package-announce - Fedora Mailing-Lists | FEDORA | lists.fedoraproject.org | Third Party Advisory |
| [security-announce] openSUSE-SU-2019:2183-1: moderate: Security update f | SUSE | lists.opensuse.org | |
| [SECURITY] Fedora 29 Update: libreoffice-6.1.6.3-3.fc29 - package-announce - Fedora Mailing-Lists | FEDORA | lists.fedoraproject.org | |
| [SECURITY] Fedora 29 Update: libreoffice-6.1.6.3-3.fc29 - package-announce - Fedora Mailing-Lists | lists.fedoraproject.org | ||
| [SECURITY] Fedora 30 Update: libreoffice-6.2.5.2-1.fc30 - package-announce - Fedora Mailing-Lists | lists.fedoraproject.org | ||
| [SECURITY] [DLA 1947-1] libreoffice security update | MLIST | lists.debian.org | |
| LibreOffice Remote Code Execution and Unauthorized Access Vulnerabilities | BID | www.securityfocus.com | Third Party Advisory |
| [security-announce] openSUSE-SU-2019:2057-1: important: Security update | SUSE | lists.opensuse.org | |
| USN-4063-1: LibreOffice vulnerabilities | Ubuntu security notices | UBUNTU | usn.ubuntu.com | Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: Thanks to Matei "Mal" Badanoiu for discovering and reporting this problem
Legacy QID Mappings
- 356235 Amazon Linux Security Advisory for libreoffice : ALASLIBREOFFICE-2023-002
- 377399 Alibaba Cloud Linux Security Update for libreoffice (ALINUX3-SA-2022:0038)
- 377446 Alibaba Cloud Linux Security Update for libreoffice (ALINUX2-SA-2020:0048)
- 501052 Alpine Linux Security Update for libreoffice
- 505018 Alpine Linux Security Update for libreoffice
- 670188 EulerOS Security Update for libreoffice (EulerOS-SA-2021-1687)
- 670883 EulerOS Security Update for libreoffice (EulerOS-SA-2021-1687)
- 710147 Gentoo Linux LibreOffice Multiple vulnerabilities (GLSA 201908-13)