LibreOffice Vulnerabilities Let Attackers Write to Arbitrary File & Extract Values

Cyber Security News is a Dedicated News Platform For Cyber News, Cyber Attack News, Hacking News & Vulnerability Analysis. For enterprises, integrating security tools like intrusion detection systems (IDS) to monitor LibreOffice’s file operations is critical. While the .ttf extension limits immediate code execution, this flaw enables server-side attacks by overwriting web application files or configuration scripts. These flaws affect both desktop users and server-side implementations, posing significant risks to enterprises and individual users relying on the open-source Office suite. Attackers can exploit this by injecting path traversal sequences into font declarations, allowing arbitrary .ttf file writes outside the designated temporary directory. According to Codean Labs, the vulnerability originates from improper sanitization of user-supplied font names in OpenDocument XML files. Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. The second vulnerability leverages LibreOffice’s handling of the vnd.sun.star.expand the URI scheme, which supports recursive variable substitution. Attackers can craft documents that extract environment variables, configuration files, or secrets via manipulated URLs. This scheme parses INI files laxly, enabling exfiltration from non-INIs like .bash_history or SQLite databases. A proof-of-concept attack demonstrated the theft of WordPress password-reset tokens from Thunderbird emails, allowing account takeover. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

This Cyber News was published on cybersecuritynews.com. Publication date: Tue, 18 Feb 2025 07:40:06 +0000


Cyber News related to LibreOffice Vulnerabilities Let Attackers Write to Arbitrary File & Extract Values

CVE-2021-36845 - Multiple Authenticated Stored Cross-Site Scripting (XSS) vulnerabilities in YITH Maintenance Mode (WordPress plugin) versions < 1.3.8, there are 46 vulnerable parameters that were missed by the vendor while patching the 1.3.7 version to 1.3.8. ...
3 years ago
LibreOffice Vulnerabilities Let Attackers Execute Malicious Files on Windows Systems - A critical security vulnerability in LibreOffice (CVE-2025-0514) has been patched after researchers discovered that manipulated documents could bypass safeguards and execute malicious files on Windows systems. The flaw, rated 7.2 on the CVSS v4.0 ...
2 weeks ago Cybersecuritynews.com CVE-2025-0514 CVE-2018-6871
CVE-2025-1080 - LibreOffice supports Office URI Schemes to enable browser integration of LibreOffice with MS SharePoint server. An additional scheme 'vnd.libreoffice.command' specific to LibreOffice was added. In the affected versions of LibreOffice a link ...
1 week ago
CVE-2022-3140 - LibreOffice supports Office URI Schemes to enable browser integration of LibreOffice with MS SharePoint server. An additional scheme 'vnd.libreoffice.command' specific to LibreOffice was added. In the affected versions of LibreOffice links ...
1 year ago
CVE-2024-5261 - Improper Certificate Validation vulnerability in LibreOffice "LibreOfficeKit" mode disables TLS certification verification ...
8 months ago
LibreOffice Vulnerabilities Let Attackers Write to Arbitrary File & Extract Values - Cyber Security News is a Dedicated News Platform For Cyber News, Cyber Attack News, Hacking News & Vulnerability Analysis. For enterprises, integrating security tools like intrusion detection systems (IDS) to monitor LibreOffice’s file operations ...
3 weeks ago Cybersecuritynews.com
CVE-2024-55642 - In the Linux kernel, the following vulnerability has been resolved: block: Prevent potential deadlocks in zone write plug error recovery Zone write plugging for handling writes to zones of a zoned block device always execute a zone report whenever a ...
2 months ago Tenable.com
CVE-2020-12801 - If LibreOffice has an encrypted document open and crashes, that document is auto-saved encrypted. On restart, LibreOffice offers to restore the document and prompts for the password to decrypt it. If the recovery is successful, and if the file format ...
1 year ago
CVE-2007-0228 - The DataCollector service in EIQ Networks Network Security Analyzer allows remote attackers to cause a denial of service (service crash) via a (1) &CONNECTSERVER& (2) &ADDENTRY& (3) &FIN& (4) &START& (5) ...
7 years ago
Wordfence Intelligence Weekly WordPress Vulnerability Report (September 23, 2024 to September 29, 2024) - Software Name Software Slug 012 Ps Multi Languages 012-ps-multi-languages ABC APP CREATOR abcapp-creator Absolute Reviews absolute-reviews Accordion accordions Ads by WPQuads – Adsense Ads, Banner Ads, Popup Ads quick-adsense-reloaded Advanced File ...
5 months ago Wordfence.com Slug
CVE-2019-13363 - admin.php?pagenotification_by_mail in Piwigo 2.9.5 has XSS via the nbm&#95;send&#95;html&#95;mail, nbm&#95;send&#95;mail&#95;as, nbm&#95;send&#95;detailed&#95;content, ...
2 years ago
CVE-2023-52587 - In the Linux kernel, the following vulnerability has been resolved: ...
1 year ago
CVE-2019-9854 - LibreOffice has a feature where documents can specify that pre-installed macros can be executed on various script events such as mouse-over, document-open etc. Access is intended to be restricted to scripts under the share/Scripts/python, ...
4 years ago
CVE-2019-9850 - LibreOffice is typically bundled with LibreLogo, a programmable turtle vector graphics script, which can execute arbitrary python commands contained with the document it is launched from. LibreOffice also has a feature where documents can specify ...
2 years ago
CVE-2019-9855 - LibreOffice is typically bundled with LibreLogo, a programmable turtle vector graphics script, which can execute arbitrary python commands contained with the document it is launched from. LibreOffice also has a feature where documents can specify ...
2 years ago
CVE-2021-25634 - LibreOffice supports digital signatures of ODF documents and macros within documents, presenting visual aids that no alteration of the document occurred since the last signing and that the signature is valid. An Improper Certificate Validation ...
3 years ago
CVE-2023-2255 - Improper access control in editor components of The Document Foundation LibreOffice allowed an attacker to craft a document that would cause external links to be loaded without prompt. In the affected versions of LibreOffice documents that used ...
1 year ago
CVE-2021-25633 - LibreOffice supports digital signatures of ODF documents and macros within documents, presenting visual aids that no alteration of the document occurred since the last signing and that the signature is valid. An Improper Certificate Validation ...
3 years ago
CVE-2021-25636 - LibreOffice supports digital signatures of ODF documents and macros within documents, presenting visual aids that no alteration of the document occurred since the last signing and that the signature is valid. An Improper Certificate Validation ...
1 year ago
CVE-2020-28092 - PESCMS Team 2.3.2 has multiple reflected XSS via the id parameter:?gTeam&mTask&amy&status3&id,?gTeam&mTask&amy&status0&id,?gTeam&mTask&amy&status1&id,?gTeam&mTask&amy&status10&id ...
4 years ago
CVE-2019-9847 - A vulnerability in LibreOffice hyperlink processing allows an attacker to construct documents containing hyperlinks pointing to the location of an executable on the target users file system. If the hyperlink is activated by the victim the executable ...
3 years ago
CVE-2018-16858 - It was found that libreoffice before versions 6.0.7 and 6.1.3 was vulnerable to a directory traversal attack which could be used to execute arbitrary macros bundled with a document. An attacker could craft a document, which when opened by ...
5 years ago
CVE-2019-9852 - LibreOffice has a feature where documents can specify that pre-installed macros can be executed on various script events such as mouse-over, document-open etc. Access is intended to be restricted to scripts under the share/Scripts/python, ...
2 years ago
CVE-2019-9848 - LibreOffice has a feature where documents can specify that pre-installed scripts can be executed on various document events such as mouse-over, etc. LibreOffice is typically also bundled with LibreLogo, a programmable turtle vector graphics script, ...
2 years ago
CVE-2022-26305 - An Improper Certificate Validation vulnerability in LibreOffice existed where determining if a macro was signed by a trusted author was done by only matching the serial number and issuer string of the used certificate with that of a trusted ...
1 year ago

Cyber Trends (last 7 days)