imPC@ndo IT

Tracker / CVE-2015-4551

CVE-2015-4551

Medium 4.3

LibreOffice before 4.4.5 and Apache OpenOffice before 4.1.2 uses the stored LinkUpdateMode configuration information in OpenDocument Format files and templates when handling links, which might allow remote attackers to obtain sensitive information via a crafted document, which embeds data from local files into (1) Calc or (2) Writer.

Affected products and versions

apache openoffice · … → 4.1.1
canonical ubuntu_linux
debian debian_linux
libreoffice libreoffice · … → 4.4.4

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References