CVE-2022-26307
Summary
| CVE | CVE-2022-26307 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-07-25 15:15:00 UTC |
| Updated | 2023-07-11 14:35:00 UTC |
| Description | LibreOffice supports the storage of passwords for web connections in the user’s configuration database. The stored passwords are encrypted with a single master key provided by the user. A flaw in LibreOffice existed where master key was poorly encoded resulting in weakening its entropy from 128 to 43 bits making the stored passwords vulerable to a brute force attack if an attacker has access to the users stored config. This issue affects: The Document Foundation LibreOffice 7.2 versions prior to 7.2.7; 7.3 versions prior to 7.3.3. |
Risk And Classification
Problem Types: NVD-CWE-Other
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Debian | Debian Linux | 10.0 | All | All | All |
| Application | Libreoffice | Libreoffice | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| CVE-2022-26307 | LibreOffice - Free Office Suite - Based on OpenOffice - Compatible with Microsoft | MISC | www.libreoffice.org | |
| oss-security - CVE-2022-37401: Apache OpenOffice Weak Master Keys | MLIST | www.openwall.com | |
| [SECURITY] [DLA 3368-1] libreoffice security update | MLIST | lists.debian.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 160422 Oracle Enterprise Linux Security Update for libreoffice (ELSA-2023-0304)
- 181034 Debian Security Update for libreoffice (CVE-2022-26307)
- 181639 Debian Security Update for libreoffice (DLA 3368-1)
- 198976 Ubuntu Security Notification for LibreOffice Vulnerabilities (USN-5661-1)
- 199000 Ubuntu Security Notification for LibreOffice Vulnerabilities (USN-5694-1)
- 241056 Red Hat Update for libreoffice (RHSA-2023:0089)
- 241115 Red Hat Update for libreoffice (RHSA-2023:0304)
- 376798 LibreOffice Multiple Vulnerabilities
- 502565 Alpine Linux Security Update for libreoffice
- 502588 Alpine Linux Security Update for libreoffice
- 752680 SUSE Enterprise Linux Security Update for libreoffice (SUSE-SU-2022:3602-1)
- 753136 SUSE Enterprise Linux Security Update for libreoffice (SUSE-SU-2022:3650-1)
- 940875 AlmaLinux Security Update for libreoffice (ALSA-2023:0089)
- 940908 AlmaLinux Security Update for libreoffice (ALSA-2023:0304)
- 960556 Rocky Linux Security Update for libreoffice (RLSA-2023:0304)
- 960559 Rocky Linux Security Update for libreoffice (RLSA-2023:0089)