Lucene search

K
ubuntucveUbuntu.comUB:CVE-2023-36268
HistoryApr 30, 2024 - 12:00 a.m.

CVE-2023-36268

2024-04-3000:00:00
ubuntu.com
ubuntu.com
8
cve-2023-36268
the document foundation
libreoffice
remote attacker
unix

CVSS3

5.7

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H

AI Score

6.5

Confidence

High

EPSS

0

Percentile

9.0%

An issue in The Document Foundation Libreoffice v.7.4.7 allows a remote
attacker to cause a denial of service via a crafted .ppt file.

Notes

Author Note
Priority reason: Denial of service via resource exhaustion in a desktop application
mdeslaur This attack uses a powerpoint slide with 640000 images in it, which causes libreoffice to consume resources. This has a low security impact as it only causes a desktop application to consume resources.

CVSS3

5.7

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H

AI Score

6.5

Confidence

High

EPSS

0

Percentile

9.0%

Related for UB:CVE-2023-36268