[debian-lts-announce] 20230813 [SECURITY] [DLA 3526-1] libreoffice security updatemailing list
https://lists.debian.org/debian-lts-announce/2023/08/msg00014.html CVE-2023-2255
MEDIUM
Remote documents loaded without prompt via IFrame
Record summary
CVE-2023-2255 has a selected CVSS score of 5.3 (medium); EIP currently links 3 repository PoCs.
Description
Improper access control in editor components of The Document Foundation LibreOffice allowed an attacker to craft a document that would cause external links to be loaded without prompt. In the affected versions of LibreOffice documents that used "floating frames" linked to external files, would load the contents of those frames without prompting the user for permission to do so. This was inconsistent with the treatment of other linked content in LibreOffice. This issue affects: The Document Foundation LibreOffice 7.4 versions prior to 7.4.7; 7.5 versions prior to 7.5.3.
Description source: CVE List
Exploitation context
Available material
- Repository PoCs
- 3
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
LibreOfficeBrowse The Document Foundation / LibreOffice | CVE List | 7.4 to < 7.4.7 | affected |
| 7.5 to < 7.5.3 | affected |
Proofs of concept
3Repository PoCs
GitHubelweth-sec/CVE-2023-2255Repository PoCby elweth-secStars: 65Not analyzed4 files
GitHubSaintMichae64/CVE-2023-2255Repository PoCby SaintMichae64Stars: 0Not analyzed2 files
GitHubG4sp4rCS/CVE-2023-2255Repository PoCby G4sp4rCSStars: 0Not analyzed3 files
References
5nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2023-2255 GLSA-202311-15Vendor advisory
https://security.gentoo.org/glsa/202311-15 DSA-5415Vendor advisory
https://www.debian.org/security/2023/dsa-5415 libreoffice.org
https://www.libreoffice.org/about-us/security/advisories/CVE-2023-2255