Alpaquita LinuxStreamSecurity Advisory
Search Cve

CVE-2024-3044

Published: May 16, 2024Last modified: May 28, 2025

Description

Unchecked script execution in Graphic on-click binding in affected LibreOffice versions allows an attacker to create a document which without prompt will execute scripts built-into LibreOffice on clicking a graphic. Such scripts were previously deemed trusted but are now deemed untrusted.

Severity score breakdown

ParameterValue
Base score6.5
Attack VectorNETWORK
Attack complexityLOW
Privileges requiredNONE
User interactionNONE
ScopeUNCHANGED
ConfidentialityNONE
Integrity impactLOW
Availability impactLOW
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L

Status

ProductReleasePackageStatus
Alpaquita Linux23 LTSlibreoffice-headlessUnknown (7.6.3.2-r3)
Streamlibreoffice-headlessUnknown (7.6.4.1-r1)

References

ON THIS PAGE