Arbitrary file disclosure in LibreOffice - CVE-2017-3157

 

Arbitrary file disclosure in LibreOffice - CVE-2017-3157

Published: February 22, 2017


Vulnerability identifier: #VU5891
CSH Severity: Low
CVSS v4: 1.8 [CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-3157
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to obtain potentially sensitive information.

The vulnerability exists within calc and write functionality of LibreOffice when processing embedded objects during preview of files. A remote attacker can create a specially crafted document, linked to an existing file on victims system, trick the victim into opening the document, saving it and sending back to the attacker.

Successful exploitation of the vulnerability may allow an attacker to view contents of arbitrary files on the system.


Affected software

LibreOffice
OpenOffice
libreoffice (Debian package)
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Server
Ubuntu

How to mitigate CVE-2017-3157

The vulnerability is fixed in the following versions: 5.1.6, 5.2.2, and 5.3.0

libreoffice (Debian package) - update to 1:4.3.3-2+deb8u6

External References

Related Security Bulletins