Arbitrary file disclosure in LibreOffice - CVE-2017-3157

 

Arbitrary file disclosure in LibreOffice - CVE-2017-3157

Published: February 22, 2017


Vulnerability identifier: #VU5891
CSH Severity: Low
CVSS v4.0: CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2017-3157
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vendor: LibreOffice
Affected software:
LibreOffice

Detailed vulnerability description

The vulnerability allows a remote attacker to obtain potentially sensitive information.

The vulnerability exists within calc and write functionality of LibreOffice when processing embedded objects during preview of files. A remote attacker can create a specially crafted document, linked to an existing file on victims system, trick the victim into opening the document, saving it and sending back to the attacker.

Successful exploitation of the vulnerability may allow an attacker to view contents of arbitrary files on the system.


How to mitigate CVE-2017-3157

The vulnerability is fixed in the following versions: 5.1.6, 5.2.2, and 5.3.0

Sources