Macro URL arbitrary script execution
Published Oct 11, 2022
6.3
MEDIUMCVSS 3.1
EPSS 5.69%
Description
LibreOffice supports Office URI Schemes to enable browser integration of LibreOffice with MS SharePoint server. An additional scheme 'vnd.libreoffice.command' specific to LibreOffice was added. In the affected versions of LibreOffice links using that scheme could be constructed to call internal macros with arbitrary arguments. Which when clicked on, or activated by document events, could result in arbitrary script execution without warning. This issue affects: The Document Foundation LibreOffice 7.4 versions prior to 7.4.1; 7.3 versions prior to 7.3.6.
Affected products
-
- Version 7.3StatusaffectedConstraints<7.3.6
- Version 7.4StatusaffectedConstraints<7.4.1
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| The Document Foundation | LibreOffice | n/a |
|
Configuration 1
- ≥ 7.3.0 · < 7.3.6
- 7.4.0
Configuration 2
- 11.0
Configuration 3
- 35
No data.
Red Hat Enterprise Linux 8
libreoffice-1:6.4.7.2-12.el8_7
Fixed · RHSA-2023:0089
Red Hat Enterprise Linux 9
libreoffice-1:7.1.8.1-8.el9_1
Fixed · RHSA-2023:0304
Red Hat Enterprise Linux 6
libreoffice
Not affected
Red Hat Enterprise Linux 7
libreoffice
Out of support scope
Red Hat Enterprise Linux 8
libreoffice:flatpak/libreoffice
Will not fix
Red Hat Enterprise Linux 9
libreoffice:flatpak/libreoffice
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 8 | libreoffice-1:6.4.7.2-12.el8_7 | Fixed | RHSA-2023:0089 |
| Red Hat Enterprise Linux 9 | libreoffice-1:7.1.8.1-8.el9_1 | Fixed | RHSA-2023:0304 |
| Red Hat Enterprise Linux 6 | libreoffice | Not affected | n/a |
| Red Hat Enterprise Linux 7 | libreoffice | Out of support scope | n/a |
| Red Hat Enterprise Linux 8 | libreoffice:flatpak/libreoffice | Will not fix | n/a |
| Red Hat Enterprise Linux 9 | libreoffice:flatpak/libreoffice | Affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (9)
- https://access.redhat.com/security/cve/CVE-2022-3140 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2134697 Issue Tracking
- https://lists.debian.org/debian-lts-announce/2023/03/msg00022.html mailing-list
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TORANVTIWWBH3DNJR4UZATAG67KZOH32/ vendor-advisory
- https://nvd.nist.gov/vuln/detail/CVE-2022-3140
- https://security.gentoo.org/glsa/202212-04 vendor-advisoryThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2022-3140
- https://www.debian.org/security/2022/dsa-5252 vendor-advisoryThird Party Advisory
- https://www.libreoffice.org/about-us/security/advisories/CVE-2022-3140 Vendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2022-3140 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2134697 | Issue Tracking | |
| https://lists.debian.org/debian-lts-announce/2023/03/msg00022.html | mailing-list | |
| https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TORANVTIWWBH3DNJR4UZATAG67KZOH32/ | vendor-advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2022-3140 | ||
| https://security.gentoo.org/glsa/202212-04 | vendor-advisoryThird Party Advisory | |
| https://www.cve.org/CVERecord?id=CVE-2022-3140 | ||
| https://www.debian.org/security/2022/dsa-5252 | vendor-advisoryThird Party Advisory | |
| https://www.libreoffice.org/about-us/security/advisories/CVE-2022-3140 | Vendor Advisory |
Change history (0)
No recorded changes yet.