Security features bypass in LibreOffice - CVE-2024-7788
Published: September 17, 2024
Vulnerability details
The vulnerability allows a remote attacker to bypass implemented security restrictions.
The vulnerability exists due to software allows to execute macros with an invalid signature in when using a "repair mode". A remote attacker can trick the victim into recover a specially crafted file and potentially compromise the affected system.
Affected software
Debian Linux
Ubuntu
libreoffice (Ubuntu package)
libreoffice (Debian package)
How to mitigate CVE-2024-7788
libreoffice (Ubuntu package) - addressed in versions 1:6.4.7-0ubuntu0.20.04.12, 1:7.3.7-0ubuntu0.22.04.7
libreoffice (Debian package) - update to 4:7.4.7-1+deb12u5