Code Execution Flaw Found in LibreOffice, OpenOffice
#1
Quote:A researcher has identified a serious remote code execution vulnerability affecting the LibreOffice and Apache OpenOffice open-source productivity suites, but a patch has only been released for the former.

Researcher Alex Inführ discovered that a malicious actor could use specially crafted documents to execute arbitrary code without any warning message being seen by the victim. All the targeted user needs to do is open a malicious ODT file and move the mouse anywhere over the document.

The expert has published a blog post detailing his findings and a video showing how the attack works. While the post and proof-of-concept (PoC) code focus on LibreOffice, the attack can be adapted for OpenOffice as well. Inführ says both Linux and Windows systems are impacted.

The vulnerability, tracked as CVE-2018-16858, has been described as a path traversal issue that allows an attacker to execute a Python file located anywhere on the targeted system. The attack is made easier by the fact that Python is bundled with LibreOffice and OpenOffice, which means the attacker does not need to worry about this component being installed on the targeted device.

SOURCE: https://www.securityweek.com/code-execut...openoffice
[-] The following 1 user says Thank You to silversurfer for this post:
  • harlan4096
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
K-Lite Codec Pack 15.9.1 Update
Changes in 19.0.0 ...Kool — 05:00
QOwnNotes 19.1.6
25.6.1 A segmen...Kool — 15:34
Privazer 4.0.19
PrivaZer version v...Kool — 08:36
AMD announces Ryzen AI Z2 Extreme and Ry...
AMD is announcing ...harlan4096 — 08:12
AMD expands FSR4 game list to 65 titles,...
AMD adds more FSR4...harlan4096 — 08:10

[-]
Birthdays
Today's Birthdays
avatar (41)zacforat
avatar (46)NemrokReks
Upcoming Birthdays
avatar (38)Tedscolo
avatar (45)brakasig
avatar (44)JamesReshy
avatar (46)Francisemefe
avatar (39)leoniDup
avatar (38)Patrizaancem
avatar (38)biobdam
avatar (37)Barrackleve
avatar (39)Julioagopy
avatar (49)aolaupitt2558
avatar (39)storoBox
avatar (47)kinotHeemn
avatar (38)Ceballos1976
avatar (39)efynu
avatar (31)horancos

[-]
Online Staff
There are no staff members currently online.

>