CVE Published: 17/07/2019 |
CVE Updated: 16/09/2024 |
CVE Year: 2019 Source: Document Fdn. |
Vendor: Document Foundation |
Product: LibreOffice Status : PUBLISHED
CVE-2019-9848 Description
LibreOffice has a feature where documents can specify that pre-installed scripts can be executed on various document events such as mouse-over, etc. LibreOffice is typically also bundled with LibreLogo, a programmable turtle vector graphics script, which can be manipulated into executing arbitrary python commands. By using the document event feature to trigger LibreLogo to execute python contained within a document a malicious document could be constructed which would execute arbitrary python commands silently without warning. In the fixed versions, LibreLogo cannot be called from a document event handler. This issue affects: Document Foundation LibreOffice versions prior to 6.2.5.
CWE-ID: CWE Name: LibreOffice is typically bundled with LibreLogo, a programmable turtle vector graphics script, which could be leveraged to by an attacker document to silently execute arbitrary python commands Source: Document Foundation
Common Attack Pattern Enumeration and Classification (CAPEC)