Input validation error in LibreOffice - CVE-2020-12803
Published: June 9, 2020
Vulnerability details
The vulnerability allows a remote attacker to overwrite arbitrary files on the system.
The vulnerability exists due to insufficient validation of user-supplied input when processing submittable forms in ODF documents. LibreOffice allows to submit data to forms, available via the file:// URI. A remote attacker can create a specially crafted form, trick the victim into submitting it and overwrite arbitrary files on the system with privileges of the current user.
Affected software
libreoffice (Red Hat package)
libcmis (Red Hat package)
liborcus (Red Hat package)
libreoffice (Ubuntu package)
libreoffice
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for Power, little endian
Red Hat CodeReady Linux Builder for x86_64
Red Hat CodeReady Linux Builder for Power, little endian
Opensuse
Ubuntu
Fedora
How to mitigate CVE-2020-12803
libreoffice (Red Hat package) - update to 6.3.6.2-3.el8
libcmis (Red Hat package) - update to 0.5.2-1.el8
liborcus (Red Hat package) - update to 0.14.1-1.el8
libreoffice (Ubuntu package) - addressed in versions 1:6.0.7-0ubuntu0.18.04.12, 1:6.4.7-0ubuntu0.20.04.6, 1:7.3.6-0ubuntu0.22.04.2
libreoffice - update to 6.3.6.2-4.fc31