CVE-2012-5639
Publication date 20 December 2019
Last updated 24 July 2024
Ubuntu priority
Cvss 3 Severity Score
LibreOffice and OpenOffice automatically open embedded content
Status
Package | Ubuntu Release | Status |
---|---|---|
libreoffice | ||
14.04 LTS trusty | Not in release | |
openoffice.org | ||
14.04 LTS trusty | Not in release | |
Notes
jdstrand
seems more like a feature request. LibreOffice prompts the user saying that the document contains links to external data and asks if the user wants to refresh them. The prompt does not say what the files are. The external content is fetched the first time without prompting.
mdeslaur
See http://whatofhow.wordpress.com/2013/12/02/stealth-mode/ for improvement that went into 4.2. We will not be fixing this in precise, marking as ignored
Severity score breakdown
Parameter | Value |
---|---|
Base score | 6.5 · Medium |
Attack vector | Network |
Attack complexity | Low |
Privileges required | None |
User interaction | Required |
Scope | Unchanged |
Confidentiality | High |
Integrity impact | None |
Availability impact | None |
Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N |