Bug 2210186 (CVE-2023-0950) - CVE-2023-0950 libreoffice: Array index underflow in Calc formula parsing
Summary: CVE-2023-0950 libreoffice: Array index underflow in Calc formula parsing
Keywords:
Status: NEW
Alias: CVE-2023-0950
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Nobody
QA Contact:
URL:
Whiteboard:
Depends On: 2210188 2210187 2210191 2210192 2210193 2210194
Blocks: 2210116
TreeView+ depends on / blocked
 
Reported: 2023-05-26 04:24 UTC by Sandipan Roy
Modified: 2023-11-14 15:16 UTC (History)
1 user (show)

Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
A vulnerability was found in LibreOffice. Improper validation of the array index in the spreadsheet component of The Document Foundation in LibreOffice allows an attacker to craft a spreadsheet document that causes an array index underflow when loaded. In affected versions of LibreOffice, certain malformed spreadsheet formulas, such as AGGREGATE, could be created with fewer parameters passed to the formula interpreter than expected, leading to an array index underflow, in which case there is a risk that arbitrary code could be executed.
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2023:6508 0 None None None 2023-11-07 08:18:28 UTC
Red Hat Product Errata RHSA-2023:6933 0 None None None 2023-11-14 15:16:17 UTC

Description Sandipan Roy 2023-05-26 04:24:39 UTC
Improper Validation of Array Index vulnerability in the spreadsheet component of The Document Foundation LibreOffice allows an attacker to craft a spreadsheet document that will cause an array index underflow when loaded. In the affected versions of LibreOffice certain malformed spreadsheet formulas, such as AGGREGATE, could be created with less parameters passed to the formula interpreter than it expected, leading to an array index underflow, in which case there is a risk that arbitrary code could be executed. This issue affects: The Document Foundation LibreOffice 7.4 versions prior to 7.4.6; 7.5 versions prior to 7.5.1.

https://www.libreoffice.org/about-us/security/advisories/CVE-2023-0950

Comment 1 Sandipan Roy 2023-05-26 04:29:44 UTC
Created libreoffice tracking bugs for this issue:

Affects: fedora-37 [bug 2210187]
Affects: fedora-38 [bug 2210188]

Comment 4 errata-xmlrpc 2023-11-07 08:18:27 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2023:6508 https://access.redhat.com/errata/RHSA-2023:6508

Comment 5 errata-xmlrpc 2023-11-14 15:16:16 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2023:6933 https://access.redhat.com/errata/RHSA-2023:6933


Note You need to log in before you can comment on or make changes to this bug.