Ability to trust not validated macro signatures removed in high security mode
Published Aug 5, 2024
7.8
HIGHCVSS 3.1
EPSS 0.24%
Description
Certificate Validation user interface in LibreOffice allows potential vulnerability.
Signed macros are scripts that have been digitally signed by the developer using a cryptographic signature. When a document with a signed macro is opened a warning is displayed by LibreOffice before the macro is executed.
Previously if verification failed the user could fail to understand the failure and choose to enable the macros anyway.
This issue affects LibreOffice: from 24.2 before 24.2.5.
Affected products
-
- Version 24.2StatusaffectedConstraints<24.2.5
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| The Document Foundation | LibreOffice | unaffected |
|
- ≥ 24.2.0.0 · < 24.2.5.1
-
- Version 24.2StatusaffectedConstraints<24.2.5
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| The Document Foundation | LibreOffice | n/a |
|
Red Hat Enterprise Linux 8
libreoffice-1:6.4.7.2-18.el8_10
Fixed · RHSA-2024:5598
Red Hat Enterprise Linux 8.2 Advanced Update Support
libreoffice-1:6.0.6.1-22.el8_2
Fixed · RHSA-2024:5886
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
libreoffice-1:6.4.7.2-17.el8_4
Fixed · RHSA-2024:5601
Red Hat Enterprise Linux 8.4 Telecommunications Update Service
libreoffice-1:6.4.7.2-17.el8_4
Fixed · RHSA-2024:5601
Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions
libreoffice-1:6.4.7.2-17.el8_4
Fixed · RHSA-2024:5601
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support
libreoffice-1:6.4.7.2-17.el8_6
Fixed · RHSA-2024:5599
Red Hat Enterprise Linux 8.6 Telecommunications Update Service
libreoffice-1:6.4.7.2-17.el8_6
Fixed · RHSA-2024:5599
Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions
libreoffice-1:6.4.7.2-17.el8_6
Fixed · RHSA-2024:5599
Red Hat Enterprise Linux 8.8 Extended Update Support
libreoffice-1:6.4.7.2-17.el8_8
Fixed · RHSA-2024:5608
Red Hat Enterprise Linux 9
libreoffice-1:7.1.8.1-14.el9_4
Fixed · RHSA-2024:5583
Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions
libreoffice-1:7.1.8.1-13.el9_0
Fixed · RHSA-2024:5584
Red Hat Enterprise Linux 9.2 Extended Update Support
libreoffice-1:7.1.8.1-13.el9_2
Fixed · RHSA-2024:5607
Red Hat Enterprise Linux 6
libreoffice
Out of support scope
Red Hat Enterprise Linux 7
libreoffice
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 8 | libreoffice-1:6.4.7.2-18.el8_10 | Fixed | RHSA-2024:5598 |
| Red Hat Enterprise Linux 8.2 Advanced Update Support | libreoffice-1:6.0.6.1-22.el8_2 | Fixed | RHSA-2024:5886 |
| Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support | libreoffice-1:6.4.7.2-17.el8_4 | Fixed | RHSA-2024:5601 |
| Red Hat Enterprise Linux 8.4 Telecommunications Update Service | libreoffice-1:6.4.7.2-17.el8_4 | Fixed | RHSA-2024:5601 |
| Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions | libreoffice-1:6.4.7.2-17.el8_4 | Fixed | RHSA-2024:5601 |
| Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support | libreoffice-1:6.4.7.2-17.el8_6 | Fixed | RHSA-2024:5599 |
| Red Hat Enterprise Linux 8.6 Telecommunications Update Service | libreoffice-1:6.4.7.2-17.el8_6 | Fixed | RHSA-2024:5599 |
| Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions | libreoffice-1:6.4.7.2-17.el8_6 | Fixed | RHSA-2024:5599 |
| Red Hat Enterprise Linux 8.8 Extended Update Support | libreoffice-1:6.4.7.2-17.el8_8 | Fixed | RHSA-2024:5608 |
| Red Hat Enterprise Linux 9 | libreoffice-1:7.1.8.1-14.el9_4 | Fixed | RHSA-2024:5583 |
| Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions | libreoffice-1:7.1.8.1-13.el9_0 | Fixed | RHSA-2024:5584 |
| Red Hat Enterprise Linux 9.2 Extended Update Support | libreoffice-1:7.1.8.1-13.el9_2 | Fixed | RHSA-2024:5607 |
| Red Hat Enterprise Linux 6 | libreoffice | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | libreoffice | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This vulnerability requires an unlikely configuration (UX confusion on the user's part, i.e. ignoring the warning, not understanding the failure, etc.) to be actionable. As such, Red Hat considers this to be a moderate vulnerability and not an important one, per our CVE classification policy.
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
References (6)
- https://access.redhat.com/security/cve/CVE-2024-6472 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2302866 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-47565 Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2024-6472
- https://www.cve.org/CVERecord?id=CVE-2024-6472
- https://www.libreoffice.org/about-us/security/advisories/CVE-2024-6472 Vendor Advisory
Change history (0)
No recorded changes yet.