Lucene search

K
kasperskyKaspersky LabKLA10699
HistoryNov 10, 2015 - 12:00 a.m.

KLA10699 Multiple vulnerabilities in LibreOffice

2015-11-1000:00:00
Kaspersky Lab
threats.kaspersky.com
24

6.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

8.2 High

AI Score

Confidence

High

0.07 Low

EPSS

Percentile

94.0%

Multiple serious vulnerabilities have been found in LibreOffice. Malicious users can exploit these vulnerabilities to cause denial of service, execute arbitrary code or obtain sensitive information. Below is a complete list of vulnerabilities

  1. Lack of configuration restrictions at LinkUpdateMode can be exploited remotely via a specially designed ODF file to obtain sensitive information;
  2. Imteger underflow can be exploited remotely via a specially designed ODF file to cause denial of service or execute arbitrary code;
  3. Integer overflow can be exploited remotely via a specially designed DOC file to cause denial of service or execute arbitrary code.

Technical details

Vulnerability (2) can be exploited only if configuration setting β€œLoad printer settings with the document” is enabled. To exploit this vulnerability attacker can use a specially designed PrinterSetup data in ODF. Vulnerability (3) caused by storing number of document pieces in 16bit unsigned number. Sufficiently long file can cause overflow.

Original advisories

LibreOffice advisory

Related products

LibreOffice

CVE list

CVE-2015-5213 high

CVE-2015-4551 warning

CVE-2015-5212 high

Solution

Update to the latest version

Get LibreOffice

Impacts

  • ACE

Arbitrary code execution. Exploitation of vulnerabilities with this impact can lead to executing by abuser any code or commands at vulnerable machine or process.

  • OSI

Obtain sensitive information. Exploitation of vulnerabilities with this impact can lead to capturing by abuser information, critical for user or system.

  • DoS

Denial of service. Exploitation of vulnerabilities with this impact can lead to loss of system availability or critical functional fault.

Affected Products

  • LibreOffice versions earlier than 4.4.5

6.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

8.2 High

AI Score

Confidence

High

0.07 Low

EPSS

Percentile

94.0%