A flaw was found in the Libreoffice package. An attacker can craft an odb containing a "database/script" file with a SCRIPT command where the contents of the file could be written to a new file whose location was determined by the attacker.
{ "availability": "Available with Ubuntu Pro with Legacy support add-on: https://ubuntu.com/pro", "binaries": [ { "binary_name": "libhsqldb1.8.0-java", "binary_version": "1.8.0.10+dfsg-6ubuntu0.16.04.1~esm1" } ] }
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2023/UBUNTU-CVE-2023-1183.json"
{ "availability": "Available with Ubuntu Pro: https://ubuntu.com/pro", "binaries": [ { "binary_name": "libhsqldb1.8.0-java", "binary_version": "1.8.0.10+dfsg-10~18.04ubuntu0.18.04.1~esm1" } ] }
{ "availability": "Available with Ubuntu Pro: https://ubuntu.com/pro", "binaries": [ { "binary_name": "libhsqldb1.8.0-java", "binary_version": "1.8.0.10+dfsg-10ubuntu0.20.04.1~esm1" } ] }
{ "availability": "No subscription required", "binaries": [ { "binary_name": "libhsqldb1.8.0-java", "binary_version": "1.8.0.10+dfsg-11+deb12u1build0.22.04.1" } ] }