QID 376798

Date Published: 2022-08-08

QID 376798: LibreOffice Multiple Vulnerabilities

LibreOffice is a office suite application.

CVE-2022-26306: Static Initialization Vector Allows to Recover Passwords for Web Connections Without Knowing the Master Password
CVE-2022-26307: Weak Master Keys Affected versions:
7.2.0 prior to version 7.2.7
7.3.0 prior to version 7.3.3
QID Detection Logic (Authenticated):
This QID checks the vulnerable version of LibreOffice by checking the file version of file soffice.exe.

Successful exploit could compromise confidentiality, integrity and availability

  • CVSS V3 rated as Critical - 8.8 severity.
  • CVSS V2 rated as High - 7.8 severity.
  • Solution
    Customers are advised to upgrade to LibreOffice version 7.2.7/7.3.3 or later. For more information refer LibreOffice

    CVEs related to QID 376798

    Software Advisories
    Advisory ID Software Component Link
    LibreOffice URL Logo www.libreoffice.org/about-us/security/advisories/