Lucene search

K
amazonAmazonALAS-2024-2557
HistoryMay 23, 2024 - 10:04 p.m.

Medium: hsqldb

2024-05-2322:04:00
alas.aws.amazon.com
9
libreoffice flaw
odb file
script command
cve-2023-1183
hsqldb
amazon linux 2
yum update
security advisory
red hat
mitre
unix

CVSS3

5.5

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N

AI Score

6.7

Confidence

Low

EPSS

0.001

Percentile

20.6%

Issue Overview:

A flaw was found in the Libreoffice package. An attacker can craft an odb containing a “database/script” file with a SCRIPT command where the contents of the file could be written to a new file whose location was determined by the attacker. (CVE-2023-1183)

Affected Packages:

hsqldb

Note:

This advisory is applicable to Amazon Linux 2 (AL2) Core repository. Visit this FAQ section for the difference between AL2 Core and AL2 Extras advisories.

Issue Correction:
Run yum update hsqldb to update your system.

New Packages:

noarch:  
    hsqldb-1.8.1.3-15.amzn2.0.3.noarch  
    hsqldb-manual-1.8.1.3-15.amzn2.0.3.noarch  
    hsqldb-javadoc-1.8.1.3-15.amzn2.0.3.noarch  
    hsqldb-demo-1.8.1.3-15.amzn2.0.3.noarch  
  
src:  
    hsqldb-1.8.1.3-15.amzn2.0.3.src  

Additional References

Red Hat: CVE-2023-1183

Mitre: CVE-2023-1183

CVSS3

5.5

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N

AI Score

6.7

Confidence

Low

EPSS

0.001

Percentile

20.6%