CVE-2019-9853

medium
Published 2020-04-28 Β· Modified 2020-04-28
CVSS v3
β€”
CVSS v4 NEW
β€”
not yet in upstream
VIR risk
5.5

Description

RHSA-2020:1598: libreoffice security and bug fix update (Moderate)

Predictions

Exploit likelihood
20%
Patch ETA
β€”

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

Mitigation details

Source: Red Hat Errata β€” Red Hat Inc. Β· View original β†— Β· Open-Errata-API

Description libreoffice: Insufficient URL decoding flaw in categorizing macro location CVSS v3: 7.8 (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H) Errata / fixed releases ProductPackageAdvisoryReleased Red Hat Enterprise Linux 7libreoffice-1:5.3.6.1-24.el7RHSA-2020:11512020-03-31T00:00:00Z Red Hat Enterprise Linux 8libreoffice-1:6.0.6.1-20.el8RHSA-2020:15982020-04-28T00:00:00Z Package state…

Description

libreoffice: Insufficient URL decoding flaw in categorizing macro location

CVSS v3: 7.8 (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)

Errata / fixed releases

ProductPackageAdvisoryReleased
Red Hat Enterprise Linux 7libreoffice-1:5.3.6.1-24.el7RHSA-2020:11512020-03-31T00:00:00Z
Red Hat Enterprise Linux 8libreoffice-1:6.0.6.1-20.el8RHSA-2020:15982020-04-28T00:00:00Z

Package state

ProductPackageState
Red Hat Enterprise Linux 6libreofficeOut of support scope

Apply commands

bash fix
Apply RHSA-2020:1151 for Red Hat Enterprise Linux 7
yum update -y libreoffice
# or:
dnf upgrade -y libreoffice

OS impact

OSVersionStatusFixed in
suse slesaffected
debian debianbookwormfixed1:6.3.0-1
debian debianbullseyefixed1:6.3.0-1
debian debianforkyfixed1:6.3.0-1
debian debiansidfixed1:6.3.0-1
debian debiantrixiefixed1:6.3.0-1
redhat rhel8fixed

References

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.