suse · CVE-2019-9848

Quick triage

Priority: low Published: 2021-05-30 14:26:16 UTC Updated: 2025-11-05 03:07:15 UTC

View at Official suse advisory, NVD, CVE.org · CVE detail

Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.

Tracker summary

CVE-2019-9848 severity low: SUSE including 984 source package names (libreoffice-6.2.6.2-3.21.1, libreoffice-6.2.6.2-lp150.2.16.1, …), 1181 product×package rows across 22 product lines (SUSE Linux Enterprise Desktop 12 SP4, SUSE Linux Enterprise Module for Open Buildservice Development Tools 15 SP2, … (22 product lines)): Fixed 1181.

Description:

LibreOffice has a feature where documents can specify that pre-installed scripts can be executed on various document events such as mouse-over, etc. LibreOffice is typically also bundled with LibreLogo, a programmable turtle vector graphics script, which can be manipulated into executing arbitrary python commands. By using the document event feature to trigger LibreLogo to execute python contained within a document a malicious document could be constructed which would execute arbitrary python commands silently without warning. In the fixed versions, LibreLogo cannot be called from a document event handler. This issue affects: Document Foundation LibreOffice versions prior to 6.2.5.

cvelogic Threat Intelligence