Bug 2134697 (CVE-2022-3140) - CVE-2022-3140 libreoffice: Macro URL arbitrary script execution
Summary: CVE-2022-3140 libreoffice: Macro URL arbitrary script execution
Keywords:
Status: CLOSED ERRATA
Alias: CVE-2022-3140
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 2134698 2134702 2134703 2134704 2134705 2134753 2134761 2134762
Blocks: 2134078
TreeView+ depends on / blocked
 
Reported: 2022-10-14 05:00 UTC by TEJ RATHI
Modified: 2023-01-25 13:52 UTC (History)
2 users (show)

Fixed In Version: LibreOffice 7.3.6, LibreOffice 7.4.1
Doc Type: If docs needed, set a value
Doc Text:
A vulnerability was found in LibreOffice that affects the Office URI Schemes. These schemes enable browser integration of LibreOffice with the MS SharePoint server. In LibreOffice, the links using the scheme 'vnd.libreoffice.command' could be constructed to call internal macros with arbitrary arguments, which, when clicked, or activated by document events, could result in arbitrary script execution without warning. The attacker must trick the targeted individual into opening a malicious file to trigger the exploit.
Clone Of:
Environment:
Last Closed: 2023-01-25 13:52:15 UTC
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2023:0089 0 None None None 2023-01-12 09:14:55 UTC
Red Hat Product Errata RHSA-2023:0304 0 None None None 2023-01-23 15:17:31 UTC

Description TEJ RATHI 2022-10-14 05:00:15 UTC
CVE-2022-3140 - LibreOffice supports Office URI Schemes to enable browser integration of LibreOffice with MS SharePoint server. An additional scheme 'vnd.libreoffice.command' specific to LibreOffice was added.

In the affected versions of LibreOffice links using that scheme could be constructed to call internal macros with arbitrary arguments. Which when clicked on, or activated by document events, could result in arbitrary script execution without warning.

Fixed in: LibreOffice 7.3.6/7.4.1
In versions >= 7.3.6 (and >= 7.4.1) such unwanted command URIs are blocked from  execution.

Reference:
https://www.libreoffice.org/about-us/security/advisories/CVE-2022-3140

Comment 1 TEJ RATHI 2022-10-14 05:00:42 UTC
Created libreoffice tracking bugs for this issue:

Affects: fedora-all [bug 2134698]

Comment 6 tru 2022-10-20 12:57:14 UTC
<iframe src='macro:Shell("/usr/bin/xeyes")'></iframe>
triggers the vulnerability on libreoffice-5.3.6.1-25.el7_9.x86_64

Comment 7 errata-xmlrpc 2023-01-12 09:14:54 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2023:0089 https://access.redhat.com/errata/RHSA-2023:0089

Comment 8 errata-xmlrpc 2023-01-23 15:17:30 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2023:0304 https://access.redhat.com/errata/RHSA-2023:0304

Comment 9 Product Security DevOps Team 2023-01-25 13:52:13 UTC
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):

https://access.redhat.com/security/cve/cve-2022-3140


Note You need to log in before you can comment on or make changes to this bug.