CVE-2019-9853
Summary
| CVE | CVE-2019-9853 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-09-27 16:15:00 UTC |
| Updated | 2023-11-07 03:13:00 UTC |
| Description | LibreOffice documents can contain macros. The execution of those macros is controlled by the document security settings, typically execution of macros are blocked by default. A URL decoding flaw existed in how the urls to the macros within the document were processed and categorized, resulting in the possibility to construct a document where macro execution bypassed the security settings. The documents were correctly detected as containing macros, and prompted the user to their existence within the documents, but macros within the document were subsequently not controlled by the security settings allowing arbitrary macro execution This issue affects: LibreOffice 6.2 series versions prior to 6.2.7; LibreOffice 6.3 series versions prior to 6.3.1. |
Risk And Classification
Problem Types: CWE-116
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Libreoffice | Libreoffice | All | All | All | All |
| Application | Libreoffice | Libreoffice | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Pony Mail! | MLIST | lists.apache.org | |
| Pony Mail! | lists.apache.org | ||
| Pony Mail! | MLIST | lists.apache.org | |
| Pony Mail! | lists.apache.org | ||
| Pony Mail! | lists.apache.org | ||
| Pony Mail! | MLIST | lists.apache.org | |
| [SECURITY] Fedora 29 Update: libreoffice-6.1.6.3-5.fc29 - package-announce - Fedora Mailing-Lists | FEDORA | lists.fedoraproject.org | |
| Pony Mail! | MLIST | lists.apache.org | |
| Pony Mail! | MLIST | lists.apache.org | |
| Pony Mail! | lists.apache.org | ||
| Open-Xchange App Suite / Documents Server-Side Request Forgery ≈ Packet Storm | MISC | packetstormsecurity.com | |
| Pony Mail! | lists.apache.org | ||
| [security-announce] openSUSE-SU-2019:2709-1: moderate: Security update f | SUSE | lists.opensuse.org | |
| Pony Mail! | MLIST | lists.apache.org | |
| Pony Mail! | lists.apache.org | ||
| Pony Mail! | lists.apache.org | ||
| Full Disclosure: Open-Xchange Security Advisory 2020-02-19 | FULLDISC | seclists.org | |
| Pony Mail! | MLIST | lists.apache.org | |
| CVE-2019-9853 | LibreOffice - Free Office Suite - Based on OpenOffice - Compatible with Microsoft | CONFIRM | www.libreoffice.org | Vendor Advisory |
| [SECURITY] [DLA 1947-1] libreoffice security update | MLIST | lists.debian.org | |
| Pony Mail! | lists.apache.org | ||
| Pony Mail! | MLIST | lists.apache.org | |
| Pony Mail! | MLIST | lists.apache.org | |
| Pony Mail! | lists.apache.org | ||
| Pony Mail! | MLIST | lists.apache.org | |
| Pony Mail! | lists.apache.org | ||
| [SECURITY] Fedora 29 Update: libreoffice-6.1.6.3-5.fc29 - package-announce - Fedora Mailing-Lists | lists.fedoraproject.org | ||
| Pony Mail! | MLIST | lists.apache.org | |
| Pony Mail! | lists.apache.org | ||
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: Thanks to Nils Emmerich of ERNW Research GmbH for discovering and reporting this issue