Vulnerability CVE-2022-3140: Information

Description

LibreOffice supports Office URI Schemes to enable browser integration of LibreOffice with MS SharePoint server. An additional scheme 'vnd.libreoffice.command' specific to LibreOffice was added. In the affected versions of LibreOffice links using that scheme could be constructed to call internal macros with arbitrary arguments. Which when clicked on, or activated by document events, could result in arbitrary script execution without warning. This issue affects: The Document Foundation LibreOffice 7.4 versions prior to 7.4.1; 7.3 versions prior to 7.3.6.

Severity: MEDIUM (6.3) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L

Published: Oct. 12, 2022
Modified: March 27, 2023
Error type identifier: CWE-88

Fixed packages

Package name
Branch
Fixed in version
Version from repository
Errata ID
Task #
State
LibreOfficesisyphus7.4.2.1-alt124.2.2.1-alt1ALT-PU-2022-2956-1309127Fixed
LibreOfficesisyphus_e2k6.3.0.3-alt6.E2K.96.3.0.3-alt6.E2K.10ALT-PU-2023-5744-1-Fixed
LibreOfficep107.4.2.3-alt47.4.2.3-alt4ALT-PU-2023-1241-1310389Fixed
LibreOfficep10_e2k6.3.0.3-alt6.E2K.5.16.3.0.3-alt6.E2K.8ALT-PU-2022-6584-1-Fixed
LibreOfficec10f17.4.2.3-alt47.4.2.3-alt4ALT-PU-2023-1241-1310389Fixed
LibreOffice-stillsisyphus7.3.6.2-alt17.6.6.3-alt1ALT-PU-2022-2618-1306809Fixed
LibreOffice-stillp107.3.6.2-alt17.6.6.3-alt0.p10.1ALT-PU-2022-2695-1307003Fixed
LibreOffice-stillc10f17.3.6.2-alt17.5.9.2-alt1.p10.1ALT-PU-2022-2695-1307003Fixed

References to Advisories, Solutions, and Tools

    1. Configuration 1

      cpe:2.3:a:libreoffice:libreoffice:7.4.0:*:*:*:*:*:*:*

      cpe:2.3:a:libreoffice:libreoffice:*:*:*:*:*:*:*:*
      Start including
      7.3.0
      End excliding
      7.3.6

      Configuration 2

      cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*

      Configuration 3

      cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:*