5.0 MEDIUM
- CVSS version: 3.1
- Attack vector (AV): LOCAL
- Attack complexity (AC): LOW
- Privileges required (PR): LOW
- User interaction (UI): REQUIRED
- Scope (S): UNCHANGED
- Confidentiality impact (C): NONE
- Integrity impact (I): HIGH
- Availability impact (A): NONE
Arbitrary file write
A flaw was found in the Libreoffice package. An attacker can craft an odb containing a "database/script" file with a SCRIPT command where the contents of the file could be written to a new file whose location was determined by the attacker.
References
-
-
-
-
-
http://www.openwall.com/lists/oss-security/2023/12/28/4 x_transferred
-
http://www.openwall.com/lists/oss-security/2024/01/03/4 x_transferred
-
-
-
-
-
-
-
-
-
http://www.openwall.com/lists/oss-security/2023/12/28/4 x_transferred
-
http://www.openwall.com/lists/oss-security/2024/01/03/4 x_transferred
-
-
-
-
-
http://www.openwall.com/lists/oss-security/2023/12/28/4 x_transferred
-
http://www.openwall.com/lists/oss-security/2024/01/03/4 x_transferred
Affected products
- ==7.4.6
- ==7.5.1
Matching in nixpkgs
pkgs.libreoffice-bin
Comprehensive, professional-quality productivity suite, a variant of openoffice.org
pkgs.hyphenDicts.de_AT
Hyphen dictionary for German (Austria) from LibreOffice
pkgs.hyphenDicts.de_CH
Hyphen dictionary for German (Switzerland) from LibreOffice
pkgs.hyphenDicts.de_DE
Hyphen dictionary for German (Germany) from LibreOffice
pkgs.libreoffice-fresh
Comprehensive, professional-quality productivity suite, a variant of openoffice.org
-
nixos-unstable 24.8.3.2-wrapped
- nixpkgs-unstable 24.8.3.2-wrapped
- nixos-unstable-small 24.8.3.2-wrapped
pkgs.libreoffice-still
Comprehensive, professional-quality productivity suite, a variant of openoffice.org
-
nixos-unstable 24.2.7.2-wrapped
- nixpkgs-unstable 24.2.7.2-wrapped
- nixos-unstable-small 24.2.7.2-wrapped
pkgs.hunspellDicts.cs_CZ
Hunspell dictionary for Czech (Czechia) from LibreOffice
pkgs.hunspellDicts.el_GR
Hunspell dictionary for Greek (Greece) from LibreOffice
pkgs.hunspellDicts.he_IL
Hunspell dictionary for Hebrew (Israel) from LibreOffice
pkgs.hunspellDicts.hr_HR
Hunspell dictionary for Croatian (Croatia) from LibreOffice
pkgs.hunspellDicts.hu_HU
Hunspell dictionary for Hungarian (Hungary) from LibreOffice
pkgs.hunspellDicts.id_id
Hunspell dictionary for Bahasa Indonesia (Indonesia) from LibreOffice
pkgs.hunspellDicts.nb_NO
Hunspell dictionary for Norwegian Bokmål (Norway) from LibreOffice
pkgs.hunspellDicts.nn_NO
Hunspell dictionary for Norwegian Nynorsk (Norway) from LibreOffice
pkgs.hunspellDicts.pl_PL
Hunspell dictionary for Polish (Poland) from LibreOffice
pkgs.hunspellDicts.pt_BR
Hunspell dictionary for Portuguese (Brazil) from LibreOffice
pkgs.hunspellDicts.pt_PT
Hunspell dictionary for Portuguese (Portugal) from LibreOffice
pkgs.hunspellDicts.ru_RU
Hunspell dictionary for Russian (Russian) from LibreOffice
pkgs.hunspellDicts.sk_SK
Hunspell dictionary for Slovak (Slovakia) from LibreOffice
pkgs.libreoffice-qt-fresh
Comprehensive, professional-quality productivity suite, a variant of openoffice.org
-
nixos-unstable 24.8.3.2-wrapped
- nixpkgs-unstable 24.8.3.2-wrapped
- nixos-unstable-small 24.8.3.2-wrapped
pkgs.libreoffice-qt-still
Comprehensive, professional-quality productivity suite, a variant of openoffice.org
-
nixos-unstable 24.2.7.2-wrapped
- nixpkgs-unstable 24.2.7.2-wrapped
- nixos-unstable-small 24.2.7.2-wrapped
pkgs.libreoffice-collabora
Comprehensive, professional-quality productivity suite, a variant of openoffice.org
pkgs.libreoffice-qt6-fresh
Comprehensive, professional-quality productivity suite, a variant of openoffice.org
-
nixos-unstable 24.8.3.2-wrapped
- nixpkgs-unstable 24.8.3.2-wrapped
- nixos-unstable-small 24.8.3.2-wrapped
pkgs.libreoffice-qt6-still
Comprehensive, professional-quality productivity suite, a variant of openoffice.org
-
nixos-unstable 24.2.7.2-wrapped
- nixpkgs-unstable 24.2.7.2-wrapped
- nixos-unstable-small 24.2.7.2-wrapped
pkgs.libreoffice-unwrapped
Comprehensive, professional-quality productivity suite, a variant of openoffice.org
pkgs.libreoffice-qt6-unwrapped
Comprehensive, professional-quality productivity suite, a variant of openoffice.org
pkgs.libreoffice-fresh-unwrapped
Comprehensive, professional-quality productivity suite, a variant of openoffice.org
pkgs.libreoffice-qt-fresh-unwrapped
Comprehensive, professional-quality productivity suite, a variant of openoffice.org
pkgs.libreoffice-qt6-fresh-unwrapped
Comprehensive, professional-quality productivity suite, a variant of openoffice.org
pkgs.libreoffice-qt6-still-unwrapped
Comprehensive, professional-quality productivity suite, a variant of openoffice.org
Package maintainers
-
@vlaci László Vaskó <laszlo.vasko@outlook.com>
-
@theCapypara Marco Köpcke <hello@capypara.de>
-
@7c6f434c Michael Raskin <7c6f434c@mail.ru>
-
@tricktron Thibault Gagnaux <tgagnaux@gmail.com>