CVE Vulnerabilities

CVE-2021-25631

Published: May 03, 2021 | Modified: May 12, 2021
CVSS 3.x
8.8
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS 2.x
9.3 HIGH
AV:N/AC:M/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
LOW

In the LibreOffice 7-1 series in versions prior to 7.1.2, and in the 7-0 series in versions prior to 7.0.5, the denylist can be circumvented by manipulating the link so it doesnt match the denylist but results in ShellExecute attempting to launch an executable type.

Affected Software

Name Vendor Start Version End Version
Libreoffice Libreoffice 7.0.0 (including) 7.0.5 (excluding)
Libreoffice Libreoffice 7.1.0 (including) 7.1.2 (excluding)
Libreoffice Ubuntu groovy *
Libreoffice Ubuntu trusty *
Libreoffice Ubuntu xenial *

References