CVE-2025-1080

Source
https://nvd.nist.gov/vuln/detail/CVE-2025-1080
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-1080.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2025-1080
Related
Published
2025-03-04T20:15:36Z
Modified
2025-03-04T22:46:26.391659Z
Downstream
Summary
[none]
Details

LibreOffice supports Office URI Schemes to enable browser integration of LibreOffice with MS SharePoint server. An additional scheme 'vnd.libreoffice.command' specific to LibreOffice was added. In the affected versions of LibreOffice a link in a browser using that scheme could be constructed with an embedded inner URL that when passed to LibreOffice could call internal macros with arbitrary arguments. This issue affects LibreOffice: from 24.8 before < 24.8.5, from 25.2 before < 25.2.1.

References

Affected packages

Debian:11 / libreoffice

Package

Name
libreoffice
Purl
pkg:deb/debian/libreoffice?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1:7.*

1:7.0.4-4
1:7.0.4-4+deb11u1~bpo10+1
1:7.0.4-4+deb11u1
1:7.0.4-4+deb11u2
1:7.0.4-4+deb11u3~bpo10+1
1:7.0.4-4+deb11u3
1:7.0.4-4+deb11u4~bpo10+1
1:7.0.4-4+deb11u4
1:7.0.4-4+deb11u5
1:7.0.4-4+deb11u6
1:7.0.4-4+deb11u7
1:7.0.4-4+deb11u8
1:7.0.4-4+deb11u9
1:7.0.4-4+deb11u10
1:7.0.4-4+deb11u11
1:7.0.4-4+deb11u12
1:7.1.0~alpha1-1
1:7.1.0~beta1-1
1:7.1.0~rc1-1
1:7.1.0~rc2-1
1:7.1.0~rc3-1
1:7.1.1~rc1-1
1:7.1.1~rc2-1
1:7.1.1~rc2-2
1:7.1.2~rc1-1
1:7.1.2~rc2-1
1:7.1.3~rc1-1
1:7.1.3~rc2-1
1:7.1.4~rc1-1
1:7.1.4~rc1-2
1:7.1.4~rc2-1
1:7.1.5-1
1:7.1.5-2~bpo11+1
1:7.1.5-2
1:7.2.0~beta1-1
1:7.2.0~beta1-2
1:7.2.0~beta1-3
1:7.2.0~beta1-4
1:7.2.0~rc1-1
1:7.2.0~rc2-1
1:7.2.0~rc2-2
1:7.2.0~rc2-3
1:7.2.0~rc2-4
1:7.2.0~rc3-1
1:7.2.0~rc4-1
1:7.2.0-1
1:7.2.0-2
1:7.2.0-3
1:7.2.1~rc1-1
1:7.2.1~rc1-2
1:7.2.1~rc2-1
1:7.2.1-1
1:7.2.1-2
1:7.2.1-3~bpo11+1
1:7.2.1-3
1:7.2.1-4
1:7.2.2~rc1-1
1:7.2.2~rc2-1
1:7.2.2-1~bpo11+1
1:7.2.2-1
1:7.2.3-1
1:7.2.3-2~bpo11+1
1:7.2.3-2
1:7.2.4-1
1:7.2.4-2
1:7.2.4-3
1:7.2.5-1~bpo11+1
1:7.2.5-1
1:7.3.0~alpha1-1
1:7.3.0~alpha1-2
1:7.3.0~alpha1-3
1:7.3.0~alpha1-4
1:7.3.0~alpha1-5
1:7.3.0~alpha1-6
1:7.3.0~beta1-1
1:7.3.0~beta1-2
1:7.3.0~beta1-3
1:7.3.0~beta1-4
1:7.3.0~rc1-1
1:7.3.0~rc1-2
1:7.3.0~rc2-1
1:7.3.0~rc2-2
1:7.3.0~rc2-3
1:7.3.0-1~bpo11+1
1:7.3.0-1
1:7.3.1~rc1-1
1:7.3.1-1~bpo11+1
1:7.3.1-1
1:7.3.2~rc2-1
1:7.3.3~rc1-1
1:7.3.3~rc1-2~bpo11+1
1:7.3.3~rc1-2
1:7.3.3~rc2-1
1:7.3.4~rc1-1~bpo11+1
1:7.3.4~rc1-1
1:7.3.4~rc2-1~bpo11+1
1:7.3.4~rc2-1
1:7.3.5~rc1-1~bpo11+1
1:7.3.5~rc1-1~bpo11+2
1:7.3.5~rc1-1
1:7.3.5~rc2-1~bpo11+1
1:7.3.5~rc2-1
1:7.4.0~alpha1-1
1:7.4.0~alpha1-2
1:7.4.0~beta1-1
1:7.4.0~beta1-2
1:7.4.0~beta1-3
1:7.4.0~beta1-4
1:7.4.0~rc1-1
1:7.4.0~rc1-2
1:7.4.0~rc1-3
1:7.4.0~rc2-1
1:7.4.0~rc2-2
1:7.4.0~rc2-3
1:7.4.0~rc3-1
1:7.4.1~rc1-1
1:7.4.1~rc1-2~bpo11+1
1:7.4.1~rc1-2
1:7.4.1~rc1-3~bpo11+1
1:7.4.1~rc1-3
1:7.4.1~rc2-1
1:7.4.1~rc2-2
1:7.4.1~rc2-3~bpo11+1
1:7.4.1~rc2-3
1:7.4.1-1~bpo11+1
1:7.4.1-1~bpo11+2
1:7.4.1-1
1:7.4.1-2
1:7.4.2~rc1-1
1:7.4.2~rc1-2
1:7.4.2~rc2-1
1:7.4.2~rc3-1
1:7.4.2-1
1:7.4.2-2~bpo11+1
1:7.4.2-2~bpo11+2
1:7.4.2-2
1:7.4.2-3
1:7.4.2-4
1:7.4.3~rc1-1
1:7.4.3~rc1-2
1:7.4.3~rc2-1
1:7.4.3~rc2-2
1:7.4.3-1
1:7.4.3-2~bpo11+1
1:7.4.3-2
1:7.4.3-3
1:7.4.4~rc1-1
1:7.4.4~rc2-1
1:7.4.4~rc2-2~bpo11+1
1:7.4.4~rc2-2~bpo11+2
1:7.4.4~rc2-2~bpo11+3
1:7.4.4~rc2-2
1:7.4.4-1
1:7.4.4-2
1:7.4.4-3
1:7.5.0~alpha1-1
1:7.5.0~alpha1-2
1:7.5.0~beta1-1
1:7.5.0~rc1-1
1:7.5.0~rc1-2
1:7.5.0~rc2-1
1:7.5.0~rc2-2
1:7.5.0~rc2-3

2:7.*

2:7.4.4-4
2:7.4.4-5
2:7.4.4-6
2:7.5.0~rc2-4

3:7.*

3:7.5.0~rc2-5
3:7.5.0~rc2-6

4:7.*

4:7.4.4-7
4:7.4.4-8
4:7.4.5-1~bpo11+1
4:7.4.5-1
4:7.4.5-2
4:7.4.5-3~bpo11+1
4:7.4.5-3
4:7.4.7-1~bpo11+1
4:7.4.7-1
4:7.5.0~rc2-7
4:7.5.0~rc3-1
4:7.5.1~rc1-1
4:7.5.1~rc2-1
4:7.5.2~rc1-1
4:7.5.2~rc2-1
4:7.5.3~rc1-1
4:7.5.3~rc2-1
4:7.5.4~rc1-1
4:7.5.4~rc1-2
4:7.5.4~rc1-3
4:7.5.4~rc1-4
4:7.5.4~rc2-1
4:7.5.4-1
4:7.5.4-2
4:7.5.4-3
4:7.5.4-4
4:7.5.5~rc1-1
4:7.5.5~rc1-2
4:7.5.5~rc1-3
4:7.5.5~rc1-4
4:7.5.5~rc1-5
4:7.5.5~rc2-1
4:7.5.5-1
4:7.5.5-2
4:7.5.5-3~bpo12+1
4:7.5.5-3
4:7.5.5-4~bpo12+1
4:7.5.5-4
4:7.5.6-1~bpo12+1
4:7.5.6-1
4:7.5.7-1
4:7.5.8~rc1-1
4:7.5.8~rc1-2
4:7.5.8-1~bpo12+1
4:7.5.8-1
4:7.5.9~rc1-1~bpo12+1
4:7.5.9~rc1-1~bpo12+2
4:7.5.9~rc1-1
4:7.6.0~rc1-1
4:7.6.0~rc1-2
4:7.6.0~rc2-1
4:7.6.0~rc2-2
4:7.6.0~rc3-1
4:7.6.1~rc1-1
4:7.6.1~rc2-1
4:7.6.1~rc2-2
4:7.6.2-1
4:7.6.2-2
4:7.6.2-3
4:7.6.2-4
4:7.6.2-5
4:7.6.3~rc1-1
4:7.6.3~rc1-2
4:7.6.3~rc2-1
4:7.6.3~rc2-2
4:7.6.3-1
4:7.6.3-2
4:7.6.4~rc1-1~bpo12+1
4:7.6.4~rc1-1

4:24.*

4:24.2.0~alpha1-1
4:24.2.0~beta1-1
4:24.2.0~rc1-1
4:24.2.0~rc1-2
4:24.2.0~rc2-1
4:24.2.0~rc2-2~bpo12+1
4:24.2.0~rc2-2
4:24.2.0-1~bpo12+1
4:24.2.0-1
4:24.2.0-2
4:24.2.0-3
4:24.2.1~rc1-1
4:24.2.1~rc2-1
4:24.2.1-1
4:24.2.1-2
4:24.2.1-3
4:24.2.1-4
4:24.2.2~rc1-1
4:24.2.2~rc1-2
4:24.2.2~rc2-1
4:24.2.2~rc2-2
4:24.2.2-1
4:24.2.2-2
4:24.2.2-3
4:24.2.3~rc1-1
4:24.2.3~rc1-2
4:24.2.3~rc1-3
4:24.2.3~rc2-1
4:24.2.3-1~bpo12+1
4:24.2.3-1
4:24.2.3-2
4:24.2.4-1~bpo12+1
4:24.2.4-1
4:24.2.5-1~bpo12+1
4:24.2.5-1
4:24.2.5-2
4:24.2.5-3
4:24.2.5-4
4:24.2.6-1
4:24.2.6-2~bpo12+1
4:24.2.6-2
4:24.8.0~alpha1-1
4:24.8.0~alpha1-2
4:24.8.0~alpha1-3
4:24.8.0~alpha1-4
4:24.8.0~beta1-1
4:24.8.0~rc1-1
4:24.8.0~rc2-1
4:24.8.0~rc3-1
4:24.8.0~rc3-2
4:24.8.1~rc1-1
4:24.8.1-1
4:24.8.1-2
4:24.8.2~rc1-1
4:24.8.2-1~bpo12+1
4:24.8.2-1
4:24.8.2-2
4:24.8.3-1~bpo12+1
4:24.8.3-1
4:24.8.3-2
4:24.8.3-3
4:24.8.4-1~bpo12+1
4:24.8.4-1
4:24.8.4-2
4:24.8.4-3
4:24.8.4-4
4:24.8.5-1
4:24.8.5-2~bpo12+1
4:24.8.5-2~bpo12+2
4:24.8.5-2

4:25.*

4:25.2.0~alpha1-1
4:25.2.0~beta1-1
4:25.2.0~beta1-2
4:25.2.0~rc1-1
4:25.2.0~rc1-2
4:25.2.0~rc1-3
4:25.2.0~rc1-4
4:25.2.0~rc2-1
4:25.2.0~rc3-1
4:25.2.0~rc3-2
4:25.2.1~rc1-1
4:25.2.1~rc1-2
4:25.2.1~rc2-1
4:25.2.1-1
4:25.2.1-2

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:12 / libreoffice

Package

Name
libreoffice
Purl
pkg:deb/debian/libreoffice?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4:7.4.7-1+deb12u7

Affected versions

4:7.*

4:7.4.5-3
4:7.4.7-1~bpo11+1
4:7.4.7-1
4:7.4.7-1+deb12u1~bpo11+1
4:7.4.7-1+deb12u1
4:7.4.7-1+deb12u2~bpo11+1
4:7.4.7-1+deb12u2
4:7.4.7-1+deb12u3
4:7.4.7-1+deb12u4
4:7.4.7-1+deb12u5
4:7.4.7-1+deb12u6

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:13 / libreoffice

Package

Name
libreoffice
Purl
pkg:deb/debian/libreoffice?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4:24.8.5-1

Affected versions

4:7.*

4:7.4.5-3
4:7.4.7-1~bpo11+1
4:7.4.7-1
4:7.5.0~rc2-7
4:7.5.0~rc3-1
4:7.5.1~rc1-1
4:7.5.1~rc2-1
4:7.5.2~rc1-1
4:7.5.2~rc2-1
4:7.5.3~rc1-1
4:7.5.3~rc2-1
4:7.5.4~rc1-1
4:7.5.4~rc1-2
4:7.5.4~rc1-3
4:7.5.4~rc1-4
4:7.5.4~rc2-1
4:7.5.4-1
4:7.5.4-2
4:7.5.4-3
4:7.5.4-4
4:7.5.5~rc1-1
4:7.5.5~rc1-2
4:7.5.5~rc1-3
4:7.5.5~rc1-4
4:7.5.5~rc1-5
4:7.5.5~rc2-1
4:7.5.5-1
4:7.5.5-2
4:7.5.5-3~bpo12+1
4:7.5.5-3
4:7.5.5-4~bpo12+1
4:7.5.5-4
4:7.5.6-1~bpo12+1
4:7.5.6-1
4:7.5.7-1
4:7.5.8~rc1-1
4:7.5.8~rc1-2
4:7.5.8-1~bpo12+1
4:7.5.8-1
4:7.5.9~rc1-1~bpo12+1
4:7.5.9~rc1-1~bpo12+2
4:7.5.9~rc1-1
4:7.6.0~rc1-1
4:7.6.0~rc1-2
4:7.6.0~rc2-1
4:7.6.0~rc2-2
4:7.6.0~rc3-1
4:7.6.1~rc1-1
4:7.6.1~rc2-1
4:7.6.1~rc2-2
4:7.6.2-1
4:7.6.2-2
4:7.6.2-3
4:7.6.2-4
4:7.6.2-5
4:7.6.3~rc1-1
4:7.6.3~rc1-2
4:7.6.3~rc2-1
4:7.6.3~rc2-2
4:7.6.3-1
4:7.6.3-2
4:7.6.4~rc1-1~bpo12+1
4:7.6.4~rc1-1

4:24.*

4:24.2.0~alpha1-1
4:24.2.0~beta1-1
4:24.2.0~rc1-1
4:24.2.0~rc1-2
4:24.2.0~rc2-1
4:24.2.0~rc2-2~bpo12+1
4:24.2.0~rc2-2
4:24.2.0-1~bpo12+1
4:24.2.0-1
4:24.2.0-2
4:24.2.0-3
4:24.2.1~rc1-1
4:24.2.1~rc2-1
4:24.2.1-1
4:24.2.1-2
4:24.2.1-3
4:24.2.1-4
4:24.2.2~rc1-1
4:24.2.2~rc1-2
4:24.2.2~rc2-1
4:24.2.2~rc2-2
4:24.2.2-1
4:24.2.2-2
4:24.2.2-3
4:24.2.3~rc1-1
4:24.2.3~rc1-2
4:24.2.3~rc1-3
4:24.2.3~rc2-1
4:24.2.3-1~bpo12+1
4:24.2.3-1
4:24.2.3-2
4:24.2.4-1~bpo12+1
4:24.2.4-1
4:24.2.5-1~bpo12+1
4:24.2.5-1
4:24.2.5-2
4:24.2.5-3
4:24.2.5-4
4:24.2.6-1
4:24.2.6-2~bpo12+1
4:24.2.6-2
4:24.8.0~alpha1-1
4:24.8.0~alpha1-2
4:24.8.0~alpha1-3
4:24.8.0~alpha1-4
4:24.8.0~beta1-1
4:24.8.0~rc1-1
4:24.8.0~rc2-1
4:24.8.0~rc3-1
4:24.8.0~rc3-2
4:24.8.1~rc1-1
4:24.8.1-1
4:24.8.1-2
4:24.8.2~rc1-1
4:24.8.2-1~bpo12+1
4:24.8.2-1
4:24.8.2-2
4:24.8.3-1~bpo12+1
4:24.8.3-1
4:24.8.3-2
4:24.8.3-3
4:24.8.4-1~bpo12+1
4:24.8.4-1
4:24.8.4-2
4:24.8.4-3
4:24.8.4-4

Ecosystem specific

{
    "urgency": "not yet assigned"
}