Lucene search

K
ubuntucveUbuntu.comUB:CVE-2023-6186
HistoryDec 11, 2023 - 12:00 a.m.

CVE-2023-6186

2023-12-1100:00:00
ubuntu.com
ubuntu.com
29
libreoffice
macro permission
validation
cve-2023-6186
security
unix

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

8.7

Confidence

High

EPSS

0.001

Percentile

28.5%

Insufficient macro permission validation of The Document Foundation
LibreOffice allows an attacker to execute built-in macros without warning.
In affected versions LibreOffice supports hyperlinks with macro or similar
built-in command targets that can be executed when activated without
warning the user.

OSVersionArchitecturePackageVersionFilename
ubuntu20.04noarchlibreoffice< 1:6.4.7-0ubuntu0.20.04.9UNKNOWN
ubuntu22.04noarchlibreoffice< 1:7.3.7-0ubuntu0.22.04.4UNKNOWN
ubuntu23.04noarchlibreoffice< 4:7.5.9-0ubuntu0.23.04.1UNKNOWN
ubuntu23.10noarchlibreoffice< 4:7.6.4-0ubuntu0.23.10.1UNKNOWN

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

8.7

Confidence

High

EPSS

0.001

Percentile

28.5%