KLA49330
Multiple vulnerabilities in LibreOffice

Updated: 05/31/2023
Detect date
?
05/24/2023
Severity
?
Warning
Description

Multiple vulnerabilities were found in LibreOffice. Malicious users can exploit these vulnerabilities to bypass security restrictions, execute arbitrary code.

Below is a complete list of vulnerabilities:

  1. Improper Access Control vulnerability in IFrame can be exploited to bypass security restrictions.
  2. Improper Validation of Array Index vulnerability in Calc Formula Parsing can be exploited remotely to execute arbitrary code.
Affected products

LibreOffice earlier than 7.4.7
LibreOffice 7.5.x earlier than 7.5.3

Solution

Update to the latest version
Download LibreOffice

Original advisories

Array Index UnderFlow in Calc Formula Parsing
Remote documents loaded without prompt via IFrame

Impacts
?
ACE 
[?]

SB 
[?]

PE 
[?]
Related products
LibreOffice
CVE-IDS
?
CVE-2023-22555.0Critical
CVE-2023-09505.0Critical
Find out the statistics of the vulnerabilities spreading in your region