CVE-2020-12803

Source
https://nvd.nist.gov/vuln/detail/CVE-2020-12803
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2020-12803.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2020-12803
Related
Published
2020-06-08T16:15:10Z
Modified
2024-10-12T05:50:15.717142Z
Severity
  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N CVSS Calculator
Summary
[none]
Details

ODF documents can contain forms to be filled out by the user. Similar to HTML forms, the contained form data can be submitted to a URI, for example, to an external web server. To create submittable forms, ODF implements the XForms W3C standard, which allows data to be submitted without the need for macros or other active scripting Prior to version 6.4.4 LibreOffice allowed forms to be submitted to any URI, including file: URIs, enabling form submissions to overwrite local files. User-interaction is required to submit the form, but to avoid the possibility of malicious documents engineered to maximize the possibility of inadvertent user submission this feature has now been limited to http[s] URIs, removing the possibility to overwrite local files. This issue affects: The Document Foundation LibreOffice versions prior to 6.4.4.

References

Affected packages

Debian:11 / libreoffice

Package

Name
libreoffice
Purl
pkg:deb/debian/libreoffice?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1:6.4.4-1

Ecosystem specific

{
    "urgency": "low"
}

Debian:12 / libreoffice

Package

Name
libreoffice
Purl
pkg:deb/debian/libreoffice?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1:6.4.4-1

Ecosystem specific

{
    "urgency": "low"
}

Debian:13 / libreoffice

Package

Name
libreoffice
Purl
pkg:deb/debian/libreoffice?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1:6.4.4-1

Ecosystem specific

{
    "urgency": "low"
}

Git / github.com/libreoffice/core

Affected ranges

Type
GIT
Repo
https://github.com/libreoffice/core
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

Other

MELD_LIBREOFFICE_REPOS
libreoffice-3-5-branch-point
libreoffice-3-6-branch-point
libreoffice-4-0-branch-point
libreoffice-4-1-branch-point
libreoffice-4-2-branch-point
libreoffice-4-2-milestone-1
libreoffice-4-3-branch-point
libreoffice-4-4-branch-point
libreoffice-5-0-branch-point
libreoffice-5-1-branch-point
libreoffice-5-2-branch-point
libreoffice-5-3-branch-point
libreoffice-5-4-branch-point
libreoffice-6-0-branch-point
libreoffice-6-1-branch-point
libreoffice-6-2-branch-point
libreoffice-6-3-branch-point
libreoffice-6-4-branch-point
windows_build_successful_2011_11_08

calc_libreoffice-3.*

calc_libreoffice-3.4.2.2-buildfix1

co-6.*

co-6.4-1
co-6.4-2
co-6.4-3

cp-6.*

cp-6.4-branch-point

gpg4libre-review-5.*

gpg4libre-review-5.4.99

libreoffice-3.*

libreoffice-3.5.0.0

libs-extern-sys_libreoffice-3.*

libs-extern-sys_libreoffice-3.4.2.2-buildfix1

libs-extern_libreoffice-3.*

libs-extern_libreoffice-3.4.2.2-buildfix1

sdremote-2.*

sdremote-2.0.0

testing_libreoffice-3.*

testing_libreoffice-3.3.99.4-hotfixes1