Lucene search

K
ubuntucveUbuntu.comUB:CVE-2017-3157
HistoryFeb 22, 2017 - 12:00 a.m.

CVE-2017-3157

2017-02-2200:00:00
ubuntu.com
ubuntu.com
12

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

5.5 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

0.001 Low

EPSS

Percentile

29.5%

By exploiting the way Apache OpenOffice before 4.1.4 renders embedded
objects, an attacker could craft a document that allows reading in a file
from the user’s filesystem. Information could be retrieved by the attacker
by, e.g., using hidden sections to store the information, tricking the user
into saving the document and convincing the user to send the document back
to the attacker. The vulnerability is mitigated by the need for the
attacker to know the precise file path in the target system, and the need
to trick the user into saving the document and sending it back.

OSVersionArchitecturePackageVersionFilename
ubuntu12.04noarchlibreoffice< 1:3.5.7-0ubuntu13UNKNOWN
ubuntu14.04noarchlibreoffice< 1:4.2.8-0ubuntu5UNKNOWN
ubuntu16.04noarchlibreoffice< 1:5.1.6~rc2-0ubuntu1~xenial1UNKNOWN

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

5.5 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

0.001 Low

EPSS

Percentile

29.5%