Lucene search

K
ubuntuUbuntuUSN-5661-1
HistoryOct 06, 2022 - 12:00 a.m.

LibreOffice vulnerabilities

2022-10-0600:00:00
ubuntu.com
30
libreoffice
ubuntu 20.04 lts
macro signatures
remote attacker
arbitrary macros
cve-2022-26305
encrypting master key
local attacker
password access
cve-2022-26306
configuration data

8.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

8.6 High

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

61.4%

Releases

  • Ubuntu 20.04 LTS

Packages

  • libreoffice - Office productivity suite

Details

It was discovered that LibreOffice incorrectly validated macro signatures.
If a user were tricked into opening a specially crafted document, a remote
attacker could possibly use this issue to execute arbitrary macros.
(CVE-2022-26305)

It was discovered that Libreoffice incorrectly handled encrypting the
master key provided by the user for storing passwords for web connections.
A local attacker could possibly use this issue to obtain access to
passwords stored in the user’s configuration data. (CVE-2022-26306,
CVE-2022-26307)

OSVersionArchitecturePackageVersionFilename
Ubuntu20.04noarchlibreoffice< 1:6.4.7-0ubuntu0.20.04.5UNKNOWN
Ubuntu20.04noarchfonts-opensymbol< 2:102.11+LibO6.4.7-0ubuntu0.20.04.5UNKNOWN
Ubuntu20.04noarchgir1.2-lokdocview-0.1< 1:6.4.7-0ubuntu0.20.04.5UNKNOWN
Ubuntu20.04noarchlibjuh-java< 1:6.4.7-0ubuntu0.20.04.5UNKNOWN
Ubuntu20.04noarchlibjurt-java< 1:6.4.7-0ubuntu0.20.04.5UNKNOWN
Ubuntu20.04noarchliblibreofficekitgtk< 1:6.4.7-0ubuntu0.20.04.5UNKNOWN
Ubuntu20.04noarchliblibreofficekitgtk-dbgsym< 1:6.4.7-0ubuntu0.20.04.5UNKNOWN
Ubuntu20.04noarchlibofficebean-java< 1:6.4.7-0ubuntu0.20.04.5UNKNOWN
Ubuntu20.04noarchlibofficebean-java-dbgsym< 1:6.4.7-0ubuntu0.20.04.5UNKNOWN
Ubuntu20.04noarchlibreoffice-avmedia-backend-gstreamer< 1:6.4.7-0ubuntu0.20.04.5UNKNOWN
Rows per page:
1-10 of 2511

8.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

8.6 High

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

61.4%