CVE-2019-9854

NameCVE-2019-9854
DescriptionLibreOffice has a feature where documents can specify that pre-installed macros can be executed on various script events such as mouse-over, document-open etc. Access is intended to be restricted to scripts under the share/Scripts/python, user/Scripts/python sub-directories of the LibreOffice install. Protection was added, to address CVE-2019-9852, to avoid a directory traversal attack where scripts in arbitrary locations on the file system could be executed by employing a URL encoding attack to defeat the path verification step. However this protection could be bypassed by taking advantage of a flaw in how LibreOffice assembled the final script URL location directly from components of the passed in path as opposed to solely from the sanitized output of the path verification step. This issue affects: Document Foundation LibreOffice 6.2 versions prior to 6.2.7; 6.3 versions prior to 6.3.1.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, Mageia, GitHub code/issues, web search, more)
ReferencesDLA-1947-1, DSA-4519-1
NVD severityhigh

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
libreoffice (PTS)jessie1:4.3.3-2+deb8u11vulnerable
jessie (security)1:4.3.3-2+deb8u13fixed
stretch1:5.2.7-1+deb9u10vulnerable
stretch (security)1:5.2.7-1+deb9u11fixed
buster1:6.1.5-3+deb10u3vulnerable
buster (security)1:6.1.5-3+deb10u4fixed
bullseye, sid1:6.3.3-2fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
libreofficesource(unstable)1:6.3.1~rc2-1
libreofficesourcebuster1:6.1.5-3+deb10u4DSA-4519-1
libreofficesourcejessie1:4.3.3-2+deb8u13DLA-1947-1
libreofficesourcestretch1:5.2.7-1+deb9u11DSA-4519-1

Notes

https://www.libreoffice.org/about-us/security/advisories/cve-2019-9854/

Search for package or bug name: Reporting problems