Bug 2349906 (CVE-2025-1080) - CVE-2025-1080 libreoffice: Macro URL arbitrary script execution
Summary: CVE-2025-1080 libreoffice: Macro URL arbitrary script execution
Keywords:
Status: NEW
Alias: CVE-2025-1080
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On: 2350028 2350029
Blocks:
TreeView+ depends on / blocked
 
Reported: 2025-03-04 21:01 UTC by OSIDB Bzimport
Modified: 2025-04-03 01:29 UTC (History)
0 users

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2025:2868 0 None None None 2025-03-17 02:05:21 UTC
Red Hat Product Errata RHSA-2025:3169 0 None None None 2025-03-25 16:58:44 UTC
Red Hat Product Errata RHSA-2025:3265 0 None None None 2025-03-26 14:02:42 UTC
Red Hat Product Errata RHSA-2025:3267 0 None None None 2025-03-26 14:48:14 UTC
Red Hat Product Errata RHSA-2025:3269 0 None None None 2025-03-26 15:13:16 UTC
Red Hat Product Errata RHSA-2025:3390 0 None None None 2025-03-31 02:11:09 UTC
Red Hat Product Errata RHSA-2025:3408 0 None None None 2025-03-31 14:42:26 UTC
Red Hat Product Errata RHSA-2025:3548 0 None None None 2025-04-03 01:27:13 UTC
Red Hat Product Errata RHSA-2025:3549 0 None None None 2025-04-03 01:29:42 UTC
Red Hat Product Errata RHSA-2025:3550 0 None None None 2025-04-03 01:26:34 UTC

Description OSIDB Bzimport 2025-03-04 21:01:05 UTC
LibreOffice supports Office URI Schemes to enable browser integration of LibreOffice with MS SharePoint server. An additional scheme 'vnd.libreoffice.command' specific to LibreOffice was added. In the affected versions of LibreOffice a link in a browser using that scheme could be constructed with an embedded inner URL that when passed to LibreOffice could call internal macros with arbitrary arguments.
This issue affects LibreOffice: from 24.8 before < 24.8.5, from 25.2 before < 25.2.1.

Comment 2 errata-xmlrpc 2025-03-17 02:05:20 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2025:2868 https://access.redhat.com/errata/RHSA-2025:2868

Comment 3 errata-xmlrpc 2025-03-25 16:58:43 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.8 Extended Update Support

Via RHSA-2025:3169 https://access.redhat.com/errata/RHSA-2025:3169

Comment 4 errata-xmlrpc 2025-03-26 14:02:41 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.2 Advanced Update Support

Via RHSA-2025:3265 https://access.redhat.com/errata/RHSA-2025:3265

Comment 5 errata-xmlrpc 2025-03-26 14:48:13 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
  Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions
  Red Hat Enterprise Linux 8.4 Telecommunications Update Service

Via RHSA-2025:3267 https://access.redhat.com/errata/RHSA-2025:3267

Comment 6 errata-xmlrpc 2025-03-26 15:13:16 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support
  Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions
  Red Hat Enterprise Linux 8.6 Telecommunications Update Service

Via RHSA-2025:3269 https://access.redhat.com/errata/RHSA-2025:3269

Comment 8 errata-xmlrpc 2025-03-31 02:11:08 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 7 Extended Lifecycle Support

Via RHSA-2025:3390 https://access.redhat.com/errata/RHSA-2025:3390

Comment 9 errata-xmlrpc 2025-03-31 14:42:25 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2025:3408 https://access.redhat.com/errata/RHSA-2025:3408

Comment 10 errata-xmlrpc 2025-04-03 01:26:33 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions

Via RHSA-2025:3550 https://access.redhat.com/errata/RHSA-2025:3550

Comment 11 errata-xmlrpc 2025-04-03 01:27:12 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.4 Extended Update Support

Via RHSA-2025:3548 https://access.redhat.com/errata/RHSA-2025:3548

Comment 12 errata-xmlrpc 2025-04-03 01:29:41 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.2 Extended Update Support

Via RHSA-2025:3549 https://access.redhat.com/errata/RHSA-2025:3549


Note You need to log in before you can comment on or make changes to this bug.