CVE-2019-9850
Summary
| CVE | CVE-2019-9850 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-08-15 22:15:00 UTC |
| Updated | 2023-11-07 03:13:00 UTC |
| Description | LibreOffice is typically bundled with LibreLogo, a programmable turtle vector graphics script, which can execute arbitrary python commands contained with the document it is launched from. LibreOffice also has a feature where documents can specify that pre-installed scripts can be executed on various document script events such as mouse-over, etc. Protection was added, to address CVE-2019-9848, to block calling LibreLogo from script event handers. However an insufficient url validation vulnerability in LibreOffice allowed malicious to bypass that protection and again trigger calling LibreLogo from script event handlers. This issue affects: Document Foundation LibreOffice versions prior to 6.2.6. |
Risk And Classification
Problem Types: CWE-20
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Canonical | Ubuntu Linux | 16.04 | All | All | All |
| Operating System | Canonical | Ubuntu Linux | 16.04 | All | All | All |
| Operating System | Canonical | Ubuntu Linux | 18.04 | All | All | All |
| Operating System | Canonical | Ubuntu Linux | 19.04 | All | All | All |
| Operating System | Canonical | Ubuntu Linux | 16.04 | All | All | All |
| Operating System | Canonical | Ubuntu Linux | 18.04 | All | All | All |
| Operating System | Canonical | Ubuntu Linux | 19.04 | All | All | All |
| Operating System | Debian | Debian Linux | 10.0 | All | All | All |
| Operating System | Debian | Debian Linux | 8.0 | All | All | All |
| Operating System | Debian | Debian Linux | 9.0 | All | All | All |
| Operating System | Debian | Debian Linux | 10.0 | All | All | All |
| Operating System | Debian | Debian Linux | 9.0 | All | All | All |
| Operating System | Fedoraproject | Fedora | 29 | All | All | All |
| Operating System | Fedoraproject | Fedora | 30 | All | All | All |
| Operating System | Fedoraproject | Fedora | 29 | All | All | All |
| Operating System | Fedoraproject | Fedora | 30 | All | All | All |
| Application | Libreoffice | Libreoffice | All | All | All | All |
| Application | Libreoffice | Libreoffice | All | All | All | All |
| Operating System | Opensuse | Leap | 15.0 | All | All | All |
| Operating System | Opensuse | Leap | 15.1 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| [SECURITY] Fedora 30 Update: libreoffice-6.2.6.2-1.fc30 - package-announce - Fedora Mailing-Lists | FEDORA | lists.fedoraproject.org | Mailing List, Third Party Advisory |
| CVE-2019-9850 | LibreOffice - Free Office Suite - Fun Project - Fantastic People | CONFIRM | www.libreoffice.org | Vendor Advisory |
| [security-announce] openSUSE-SU-2019:2183-1: moderate: Security update f | SUSE | lists.opensuse.org | |
| [SECURITY] Fedora 29 Update: libreoffice-6.1.6.3-3.fc29 - package-announce - Fedora Mailing-Lists | FEDORA | lists.fedoraproject.org | Mailing List, Third Party Advisory |
| [SECURITY] Fedora 29 Update: libreoffice-6.1.6.3-3.fc29 - package-announce - Fedora Mailing-Lists | lists.fedoraproject.org | ||
| Bugtraq: [SECURITY] [DSA 4501-1] libreoffice security update | BUGTRAQ | seclists.org | Mailing List, Third Party Advisory |
| [SECURITY] [DLA 1947-1] libreoffice security update | MLIST | lists.debian.org | |
| [SECURITY] Fedora 30 Update: libreoffice-6.2.6.2-1.fc30 - package-announce - Fedora Mailing-Lists | lists.fedoraproject.org | ||
| [security-announce] openSUSE-SU-2019:2057-1: important: Security update | SUSE | lists.opensuse.org | |
| USN-4102-1: LibreOffice vulnerabilities | Ubuntu security notices | Ubuntu | UBUNTU | usn.ubuntu.com | Third Party Advisory |
| Debian -- Security Information -- DSA-4501-1 libreoffice | DEBIAN | www.debian.org | Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: Thanks to alex (@insertscript) for reporting this issue
Legacy QID Mappings
- 356235 Amazon Linux Security Advisory for libreoffice : ALASLIBREOFFICE-2023-002
- 377399 Alibaba Cloud Linux Security Update for libreoffice (ALINUX3-SA-2022:0038)
- 377446 Alibaba Cloud Linux Security Update for libreoffice (ALINUX2-SA-2020:0048)
- 501053 Alpine Linux Security Update for libreoffice
- 505019 Alpine Linux Security Update for libreoffice