Search 219043 CVE descriptions
and 99761 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2019-9852
Description:LibreOffice has a feature where documents can specify that pre- installed macros can be executed on various script events such as mouse-over, document-open etc. Access is intended to be restricted to scripts under the share/Scripts/python, user/Scripts/python sub- directories of the LibreOffice install. Protection was added, to address CVE-2018-16858, to avoid a directory traversal attack where scripts in arbitrary locations on the file system could be executed. However this new protection could be bypassed by a URL encoding attack. In the fixed versions, the parsed url describing the script location is correctly encoded before further processing. This issue affects: Document Foundation LibreOffice versions prior to 6.2.6.
Test IDs:  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2019-9852
Bugtraq: 20190815 [SECURITY] [DSA 4501-1] libreoffice security update (Google Search)
Bugtraq: 20190910 [SECURITY] [DSA 4519-1] libreoffice security update (Google Search)
Debian Security Information: DSA-4501 (Google Search)
SuSE Security Announcement: openSUSE-SU-2019:2057 (Google Search)
SuSE Security Announcement: openSUSE-SU-2019:2183 (Google Search)

© 1998-2021 E-Soft Inc. All rights reserved.