Name | CVE-2025-1080 |
Description | LibreOffice supports Office URI Schemes to enable browser integration of LibreOffice with MS SharePoint server. An additional scheme 'vnd.libreoffice.command' specific to LibreOffice was added. In the affected versions of LibreOffice a link in a browser using that scheme could be constructed with an embedded inner URL that when passed to LibreOffice could call internal macros with arbitrary arguments. This issue affects LibreOffice: from 24.8 before < 24.8.5, from 25.2 before < 25.2.1. |
Source | CVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) |
References | DLA-4205-1, DSA-5873-1 |
The table below lists information on source packages.
Source Package | Release | Version | Status |
---|---|---|---|
libreoffice (PTS) | bullseye | 1:7.0.4-4+deb11u10 | vulnerable |
bullseye (security) | 1:7.0.4-4+deb11u13 | fixed | |
bookworm, bookworm (security) | 4:7.4.7-1+deb12u8 | fixed | |
sid, trixie | 4:25.2.3-2 | fixed |
The information below is based on the following data on fixed versions.
Package | Type | Release | Fixed Version | Urgency | Origin | Debian Bugs |
---|---|---|---|---|---|---|
libreoffice | source | bullseye | 1:7.0.4-4+deb11u13 | DLA-4205-1 | ||
libreoffice | source | bookworm | 4:7.4.7-1+deb12u7 | DSA-5873-1 | ||
libreoffice | source | (unstable) | 4:24.8.5-1 |
https://www.libreoffice.org/about-us/security/advisories/cve-2025-1080
https://gerrit.libreoffice.org/c/core/+/181016
Fixed by: https://git.libreoffice.org/core/commit/7105fb698f897ddb38bd60315444c07356689e14
Vulnerable logic (function CheckOfficeURI) introduced by: https://github.com/LibreOffice/core/commit/4311e8fb88c334cccad6f577610e1af8ae75bc59 (5.3.0.0.alpha0+)