Lucene search

K
cve[email protected]CVE-2015-4551
HistoryNov 10, 2015 - 5:59 p.m.

CVE-2015-4551

2015-11-1017:59:00
CWE-200
web.nvd.nist.gov
76
cve-2015-4551
libreoffice
apache openoffice
opendocument format
vulnerability
information security
remote attack

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

7 High

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

60.3%

LibreOffice before 4.4.5 and Apache OpenOffice before 4.1.2 uses the stored LinkUpdateMode configuration information in OpenDocument Format files and templates when handling links, which might allow remote attackers to obtain sensitive information via a crafted document, which embeds data from local files into (1) Calc or (2) Writer.

Affected configurations

NVD
Node
libreofficelibreofficeRange4.4.4
Node
canonicalubuntu_linuxMatch12.04lts
OR
canonicalubuntu_linuxMatch14.04lts
OR
canonicalubuntu_linuxMatch15.04
OR
debiandebian_linuxMatch7.0
OR
debiandebian_linuxMatch8.0
Node
apacheopenofficeRange4.1.1

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

7 High

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

60.3%