Vulnerability   
Search   
    Search 324607 CVE descriptions
and 146377 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.1.12.2022.5694.1
Category:Ubuntu Local Security Checks
Title:Ubuntu: Security Advisory (USN-5694-1)
Summary:The remote host is missing an update for the 'libreoffice' package(s) announced via the USN-5694-1 advisory.
Description:Summary:
The remote host is missing an update for the 'libreoffice' package(s) announced via the USN-5694-1 advisory.

Vulnerability Insight:
It was discovered that LibreOffice incorrectly handled links using the
Office URI Schemes. If a user were tricked into opening a specially
crafted document, a remote attacker could use this issue to execute
arbitrary scripts. (CVE-2022-3140)

Thomas Florian discovered that LibreOffice incorrectly handled crashes when
an encrypted document is open. If the document is recovered upon restarting
LibreOffice, subsequent saves of the document were unencrypted. This issue
only affected Ubuntu 18.04 LTS. (CVE-2020-12801)

Jens Muller discovered that LibreOffice incorrectly handled certain
documents containing forms. If a user were tricked into opening a specially
crafted document, a remote attacker could overwrite arbitrary files when
the form was submitted. This issue only affected Ubuntu 18.04 LTS.
(CVE-2020-12803)

It was discovered that LibreOffice incorrectly validated macro signatures.
If a user were tricked into opening a specially crafted document, a remote
attacker could possibly use this issue to execute arbitrary macros. This
issue only affected Ubuntu 18.04 LTS. (CVE-2022-26305)

It was discovered that Libreoffice incorrectly handled encrypting the
master key provided by the user for storing passwords for web connections.
A local attacker could possibly use this issue to obtain access to
passwords stored in the user's configuration data. This issue only affected
Ubuntu 18.04 LTS. (CVE-2022-26306, CVE-2022-26307)

Affected Software/OS:
'libreoffice' package(s) on Ubuntu 18.04, Ubuntu 20.04, Ubuntu 22.04.

Solution:
Please install the updated package(s).

CVSS Score:
5.0

CVSS Vector:
AV:N/AC:L/Au:N/C:P/I:N/A:N

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2020-12801
https://www.libreoffice.org/about-us/security/advisories/CVE-2020-12801
https://lists.debian.org/debian-lts-announce/2023/12/msg00026.html
SuSE Security Announcement: openSUSE-SU-2020:0786 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2020-06/msg00011.html
Common Vulnerability Exposure (CVE) ID: CVE-2020-12803
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PQIBAKXD7VO5IGBD7ZMH3GGBNR5R2IOA/
https://www.libreoffice.org/about-us/security/advisories/CVE-2020-12803
SuSE Security Announcement: openSUSE-SU-2020:1222 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00042.html
SuSE Security Announcement: openSUSE-SU-2020:1261 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00058.html
Common Vulnerability Exposure (CVE) ID: CVE-2022-26305
[debian-lts-announce] 20230326 [SECURITY] [DLA 3368-1] libreoffice security update
https://lists.debian.org/debian-lts-announce/2023/03/msg00022.html
https://www.libreoffice.org/about-us/security/advisories/cve-2022-26305
Common Vulnerability Exposure (CVE) ID: CVE-2022-26306
[oss-security] 20220812 CVE-2022-37400: Apache OpenOffice Static Initialization Vector Allows to Recover Passwords for Web Connections Without Knowing the Master Password
http://www.openwall.com/lists/oss-security/2022/08/13/1
https://www.libreoffice.org/about-us/security/advisories/cve-2022-26306
Common Vulnerability Exposure (CVE) ID: CVE-2022-26307
[oss-security] 20220812 CVE-2022-37401: Apache OpenOffice Weak Master Keys
http://www.openwall.com/lists/oss-security/2022/08/13/2
https://www.libreoffice.org/about-us/security/advisories/cve-2022-26307
Common Vulnerability Exposure (CVE) ID: CVE-2022-3140
DSA-5252
https://www.debian.org/security/2022/dsa-5252
FEDORA-2022-775c747e4a
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TORANVTIWWBH3DNJR4UZATAG67KZOH32/
GLSA-202212-04
https://security.gentoo.org/glsa/202212-04
https://www.libreoffice.org/about-us/security/advisories/CVE-2022-3140
CopyrightCopyright (C) 2022 Greenbone AG

This is only one of 146377 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.