Nils Emmerich discovered that LibreOffice incorrectly handled LibreLogo scripts. If a user were tricked into opening a specially crafted document, a remote attacker could cause LibreOffice to execute arbitrary code. (CVE-2019-9848)
Matei "Mal" Badanoiu discovered that LibreOffice incorrectly handled stealth mode. Contrary to expectations, bullet graphics could be retrieved from remote locations when running in stealth mode. (CVE-2019-9849)
{
"availability": "No subscription required",
"binaries": [
{
"binary_version": "2:102.7+LibO5.1.6~rc2-0ubuntu1~xenial8",
"binary_name": "fonts-opensymbol"
},
{
"binary_version": "1:5.1.6~rc2-0ubuntu1~xenial8",
"binary_name": "gir1.2-lokdocview-0.1"
},
{
"binary_version": "1:5.1.6~rc2-0ubuntu1~xenial8",
"binary_name": "libreoffice"
},
{
"binary_version": "1:5.1.6~rc2-0ubuntu1~xenial8",
"binary_name": "libreoffice-avmedia-backend-gstreamer"
},
{
"binary_version": "1:5.1.6~rc2-0ubuntu1~xenial8",
"binary_name": "libreoffice-base"
},
{
"binary_version": "1:5.1.6~rc2-0ubuntu1~xenial8",
"binary_name": "libreoffice-base-core"
},
{
"binary_version": "1:5.1.6~rc2-0ubuntu1~xenial8",
"binary_name": "libreoffice-base-drivers"
},
{
"binary_version": "1:5.1.6~rc2-0ubuntu1~xenial8",
"binary_name": "libreoffice-calc"
},
{
"binary_version": "1:5.1.6~rc2-0ubuntu1~xenial8",
"binary_name": "libreoffice-common"
},
{
"binary_version": "1:5.1.6~rc2-0ubuntu1~xenial8",
"binary_name": "libreoffice-core"
},
{
"binary_version": "1:5.1.6~rc2-0ubuntu1~xenial8",
"binary_name": "libreoffice-dev"
},
{
"binary_version": "1:5.1.6~rc2-0ubuntu1~xenial8",
"binary_name": "libreoffice-draw"
},
{
"binary_version": "1:5.1.6~rc2-0ubuntu1~xenial8",
"binary_name": "libreoffice-gnome"
},
{
"binary_version": "1:5.1.6~rc2-0ubuntu1~xenial8",
"binary_name": "libreoffice-gtk"
},
{
"binary_version": "1:5.1.6~rc2-0ubuntu1~xenial8",
"binary_name": "libreoffice-gtk3"
},
{
"binary_version": "1:5.1.6~rc2-0ubuntu1~xenial8",
"binary_name": "libreoffice-impress"
},
{
"binary_version": "1:5.1.6~rc2-0ubuntu1~xenial8",
"binary_name": "libreoffice-java-common"
},
{
"binary_version": "1:5.1.6~rc2-0ubuntu1~xenial8",
"binary_name": "libreoffice-kde"
},
{
"binary_version": "1:5.1.6~rc2-0ubuntu1~xenial8",
"binary_name": "libreoffice-l10n-in"
},
{
"binary_version": "1:5.1.6~rc2-0ubuntu1~xenial8",
"binary_name": "libreoffice-l10n-za"
},
{
"binary_version": "1:5.1.6~rc2-0ubuntu1~xenial8",
"binary_name": "libreoffice-librelogo"
},
{
"binary_version": "1:5.1.6~rc2-0ubuntu1~xenial8",
"binary_name": "libreoffice-math"
},
{
"binary_version": "1.0.2+LibO5.1.6~rc2-0ubuntu1~xenial8",
"binary_name": "libreoffice-mysql-connector"
},
{
"binary_version": "1:5.1.6~rc2-0ubuntu1~xenial8",
"binary_name": "libreoffice-officebean"
},
{
"binary_version": "1:5.1.6~rc2-0ubuntu1~xenial8",
"binary_name": "libreoffice-ogltrans"
},
{
"binary_version": "1:5.1.6~rc2-0ubuntu1~xenial8",
"binary_name": "libreoffice-pdfimport"
},
{
"binary_version": "1:5.1.6~rc2-0ubuntu1~xenial8",
"binary_name": "libreoffice-report-builder"
},
{
"binary_version": "1:5.1.6~rc2-0ubuntu1~xenial8",
"binary_name": "libreoffice-report-builder-bin"
},
{
"binary_version": "1:5.1.6~rc2-0ubuntu1~xenial8",
"binary_name": "libreoffice-script-provider-bsh"
},
{
"binary_version": "1:5.1.6~rc2-0ubuntu1~xenial8",
"binary_name": "libreoffice-script-provider-js"
},
{
"binary_version": "1:5.1.6~rc2-0ubuntu1~xenial8",
"binary_name": "libreoffice-script-provider-python"
},
{
"binary_version": "1:5.1.6~rc2-0ubuntu1~xenial8",
"binary_name": "libreoffice-sdbc-firebird"
},
{
"binary_version": "1:5.1.6~rc2-0ubuntu1~xenial8",
"binary_name": "libreoffice-sdbc-hsqldb"
},
{
"binary_version": "1:5.1.6~rc2-0ubuntu1~xenial8",
"binary_name": "libreoffice-sdbc-postgresql"
},
{
"binary_version": "1:5.1.6~rc2-0ubuntu1~xenial8",
"binary_name": "libreoffice-style-breeze"
},
{
"binary_version": "1:5.1.6~rc2-0ubuntu1~xenial8",
"binary_name": "libreoffice-style-elementary"
},
{
"binary_version": "1:5.1.6~rc2-0ubuntu1~xenial8",
"binary_name": "libreoffice-style-galaxy"
},
{
"binary_version": "1:5.1.6~rc2-0ubuntu1~xenial8",
"binary_name": "libreoffice-style-hicontrast"
},
{
"binary_version": "1:5.1.6~rc2-0ubuntu1~xenial8",
"binary_name": "libreoffice-style-human"
},
{
"binary_version": "1:5.1.6~rc2-0ubuntu1~xenial8",
"binary_name": "libreoffice-style-oxygen"
},
{
"binary_version": "1:5.1.6~rc2-0ubuntu1~xenial8",
"binary_name": "libreoffice-style-sifr"
},
{
"binary_version": "1:5.1.6~rc2-0ubuntu1~xenial8",
"binary_name": "libreoffice-style-tango"
},
{
"binary_version": "1:5.1.6~rc2-0ubuntu1~xenial8",
"binary_name": "libreoffice-subsequentcheckbase"
},
{
"binary_version": "1.2.0+LibO5.1.6~rc2-0ubuntu1~xenial8",
"binary_name": "libreoffice-wiki-publisher"
},
{
"binary_version": "1:5.1.6~rc2-0ubuntu1~xenial8",
"binary_name": "libreoffice-writer"
},
{
"binary_version": "1:5.1.6~rc2-0ubuntu1~xenial8",
"binary_name": "libreofficekit-dev"
},
{
"binary_version": "1:5.1.6~rc2-0ubuntu1~xenial8",
"binary_name": "python3-uno"
},
{
"binary_version": "5.1.6~rc2-0ubuntu1~xenial8",
"binary_name": "uno-libs3"
},
{
"binary_version": "5.1.6~rc2-0ubuntu1~xenial8",
"binary_name": "ure"
}
]
}
{
"ecosystem": "Ubuntu:16.04:LTS",
"cves": [
{
"id": "CVE-2019-9848",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
},
{
"type": "CVSS_V3",
"score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
},
{
"type": "Ubuntu",
"score": "medium"
}
]
},
{
"id": "CVE-2019-9849",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
},
{
"type": "CVSS_V3",
"score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
},
{
"type": "Ubuntu",
"score": "medium"
}
]
}
]
}
{
"availability": "No subscription required",
"binaries": [
{
"binary_version": "2:102.10+LibO6.0.7-0ubuntu0.18.04.8",
"binary_name": "fonts-opensymbol"
},
{
"binary_version": "1:6.0.7-0ubuntu0.18.04.8",
"binary_name": "gir1.2-lokdocview-0.1"
},
{
"binary_version": "1:6.0.7-0ubuntu0.18.04.8",
"binary_name": "liblibreofficekitgtk"
},
{
"binary_version": "1:6.0.7-0ubuntu0.18.04.8",
"binary_name": "libreoffice"
},
{
"binary_version": "1:6.0.7-0ubuntu0.18.04.8",
"binary_name": "libreoffice-avmedia-backend-gstreamer"
},
{
"binary_version": "1:6.0.7-0ubuntu0.18.04.8",
"binary_name": "libreoffice-base"
},
{
"binary_version": "1:6.0.7-0ubuntu0.18.04.8",
"binary_name": "libreoffice-base-core"
},
{
"binary_version": "1:6.0.7-0ubuntu0.18.04.8",
"binary_name": "libreoffice-base-drivers"
},
{
"binary_version": "1:6.0.7-0ubuntu0.18.04.8",
"binary_name": "libreoffice-calc"
},
{
"binary_version": "1:6.0.7-0ubuntu0.18.04.8",
"binary_name": "libreoffice-common"
},
{
"binary_version": "1:6.0.7-0ubuntu0.18.04.8",
"binary_name": "libreoffice-core"
},
{
"binary_version": "1:6.0.7-0ubuntu0.18.04.8",
"binary_name": "libreoffice-dev"
},
{
"binary_version": "1:6.0.7-0ubuntu0.18.04.8",
"binary_name": "libreoffice-dev-common"
},
{
"binary_version": "1:6.0.7-0ubuntu0.18.04.8",
"binary_name": "libreoffice-draw"
},
{
"binary_version": "1:6.0.7-0ubuntu0.18.04.8",
"binary_name": "libreoffice-evolution"
},
{
"binary_version": "1:6.0.7-0ubuntu0.18.04.8",
"binary_name": "libreoffice-gnome"
},
{
"binary_version": "1:6.0.7-0ubuntu0.18.04.8",
"binary_name": "libreoffice-gtk"
},
{
"binary_version": "1:6.0.7-0ubuntu0.18.04.8",
"binary_name": "libreoffice-gtk2"
},
{
"binary_version": "1:6.0.7-0ubuntu0.18.04.8",
"binary_name": "libreoffice-gtk3"
},
{
"binary_version": "1:6.0.7-0ubuntu0.18.04.8",
"binary_name": "libreoffice-impress"
},
{
"binary_version": "1:6.0.7-0ubuntu0.18.04.8",
"binary_name": "libreoffice-java-common"
},
{
"binary_version": "1:6.0.7-0ubuntu0.18.04.8",
"binary_name": "libreoffice-kde"
},
{
"binary_version": "1:6.0.7-0ubuntu0.18.04.8",
"binary_name": "libreoffice-kde4"
},
{
"binary_version": "1:6.0.7-0ubuntu0.18.04.8",
"binary_name": "libreoffice-l10n-in"
},
{
"binary_version": "1:6.0.7-0ubuntu0.18.04.8",
"binary_name": "libreoffice-l10n-za"
},
{
"binary_version": "1:6.0.7-0ubuntu0.18.04.8",
"binary_name": "libreoffice-librelogo"
},
{
"binary_version": "1:6.0.7-0ubuntu0.18.04.8",
"binary_name": "libreoffice-math"
},
{
"binary_version": "1.0.2+LibO6.0.7-0ubuntu0.18.04.8",
"binary_name": "libreoffice-mysql-connector"
},
{
"binary_version": "0.9+LibO6.0.7-0ubuntu0.18.04.8",
"binary_name": "libreoffice-nlpsolver"
},
{
"binary_version": "1:6.0.7-0ubuntu0.18.04.8",
"binary_name": "libreoffice-officebean"
},
{
"binary_version": "1:6.0.7-0ubuntu0.18.04.8",
"binary_name": "libreoffice-ogltrans"
},
{
"binary_version": "1:6.0.7-0ubuntu0.18.04.8",
"binary_name": "libreoffice-pdfimport"
},
{
"binary_version": "1:6.0.7-0ubuntu0.18.04.8",
"binary_name": "libreoffice-report-builder"
},
{
"binary_version": "1:6.0.7-0ubuntu0.18.04.8",
"binary_name": "libreoffice-report-builder-bin"
},
{
"binary_version": "1:6.0.7-0ubuntu0.18.04.8",
"binary_name": "libreoffice-script-provider-bsh"
},
{
"binary_version": "1:6.0.7-0ubuntu0.18.04.8",
"binary_name": "libreoffice-script-provider-js"
},
{
"binary_version": "1:6.0.7-0ubuntu0.18.04.8",
"binary_name": "libreoffice-script-provider-python"
},
{
"binary_version": "1:6.0.7-0ubuntu0.18.04.8",
"binary_name": "libreoffice-sdbc-firebird"
},
{
"binary_version": "1:6.0.7-0ubuntu0.18.04.8",
"binary_name": "libreoffice-sdbc-hsqldb"
},
{
"binary_version": "1:6.0.7-0ubuntu0.18.04.8",
"binary_name": "libreoffice-sdbc-postgresql"
},
{
"binary_version": "1:6.0.7-0ubuntu0.18.04.8",
"binary_name": "libreoffice-style-breeze"
},
{
"binary_version": "1:6.0.7-0ubuntu0.18.04.8",
"binary_name": "libreoffice-style-elementary"
},
{
"binary_version": "1:6.0.7-0ubuntu0.18.04.8",
"binary_name": "libreoffice-style-galaxy"
},
{
"binary_version": "1:6.0.7-0ubuntu0.18.04.8",
"binary_name": "libreoffice-style-hicontrast"
},
{
"binary_version": "1:6.0.7-0ubuntu0.18.04.8",
"binary_name": "libreoffice-style-human"
},
{
"binary_version": "1:6.0.7-0ubuntu0.18.04.8",
"binary_name": "libreoffice-style-oxygen"
},
{
"binary_version": "1:6.0.7-0ubuntu0.18.04.8",
"binary_name": "libreoffice-style-sifr"
},
{
"binary_version": "1:6.0.7-0ubuntu0.18.04.8",
"binary_name": "libreoffice-style-tango"
},
{
"binary_version": "1:6.0.7-0ubuntu0.18.04.8",
"binary_name": "libreoffice-subsequentcheckbase"
},
{
"binary_version": "1:6.0.7-0ubuntu0.18.04.8",
"binary_name": "libreoffice-systray"
},
{
"binary_version": "1.2.0+LibO6.0.7-0ubuntu0.18.04.8",
"binary_name": "libreoffice-wiki-publisher"
},
{
"binary_version": "1:6.0.7-0ubuntu0.18.04.8",
"binary_name": "libreoffice-writer"
},
{
"binary_version": "1:6.0.7-0ubuntu0.18.04.8",
"binary_name": "libreofficekit-data"
},
{
"binary_version": "1:6.0.7-0ubuntu0.18.04.8",
"binary_name": "libreofficekit-dev"
},
{
"binary_version": "1:6.0.7-0ubuntu0.18.04.8",
"binary_name": "python3-uno"
},
{
"binary_version": "6.0.7-0ubuntu0.18.04.8",
"binary_name": "uno-libs3"
},
{
"binary_version": "6.0.7-0ubuntu0.18.04.8",
"binary_name": "ure"
}
]
}
{
"ecosystem": "Ubuntu:18.04:LTS",
"cves": [
{
"id": "CVE-2019-9848",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
},
{
"type": "CVSS_V3",
"score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
},
{
"type": "Ubuntu",
"score": "medium"
}
]
},
{
"id": "CVE-2019-9849",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
},
{
"type": "CVSS_V3",
"score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
},
{
"type": "Ubuntu",
"score": "medium"
}
]
}
]
}