Gentoo update for LibreOffice



Risk High
Patch available YES
Number of vulnerabilities 2
CVE-ID CVE-2023-0950
CVE-2023-2255
CWE-ID CWE-129
CWE-357
Exploitation vector Network
Public exploit N/A
Vulnerable software
Gentoo Linux
Operating systems & Components / Operating system

app-office/libreoffice-bin
Operating systems & Components / Operating system package or component

app-office/libreoffice
Operating systems & Components / Operating system package or component

Vendor Gentoo

Security Bulletin

This security bulletin contains information about 2 vulnerabilities.

1) Improper validation of array index

EUVDB-ID: #VU76612

Risk: High

CVSSv4.0: 5.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber]

CVE-ID: CVE-2023-0950

CWE-ID: CWE-129 - Improper Validation of Array Index

Exploit availability: No

Description

The vulnerability allows a remote attacker to compromise the affected system.

The vulnerability exists due to improper validation of array index when malformed spreadsheet formulas, such as AGGREGATE. A remote attacker can trick the victim to open a specially crafted file, trigger an array index underflow and execute arbitrary code on the system.

Mitigation

Update the affected packages.
app-office/libreoffice to version: 7.5.3.2
app-office/libreoffice-bin to version: 7.5.3.2

Vulnerable software versions

Gentoo Linux: All versions

app-office/libreoffice-bin: before 7.5.3.2

app-office/libreoffice: before 7.5.3.2

CPE2.3 External links

https://security.gentoo.org/glsa/202311-15


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

2) Insufficient UI Warning of Dangerous Operations

EUVDB-ID: #VU76613

Risk: Medium

CVSSv4.0: 1 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Green]

CVE-ID: CVE-2023-2255

CWE-ID: CWE-357 - Insufficient UI Warning of Dangerous Operations

Exploit availability: No

Description

The vulnerability allows a remote attacker to perform spoofing attack.

The vulnerability exists due to the application allows usage of floating frames that can fetch content from external sources without prompting the user. A remote attacker can trick the victim to open a specially crafted file and perform spoofing attack.

Mitigation

Update the affected packages.
app-office/libreoffice to version: 7.5.3.2
app-office/libreoffice-bin to version: 7.5.3.2

Vulnerable software versions

Gentoo Linux: All versions

app-office/libreoffice-bin: before 7.5.3.2

app-office/libreoffice: before 7.5.3.2

CPE2.3 External links

https://security.gentoo.org/glsa/202311-15


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.



###SIDEBAR###