CVE-2023-1183

medium
Published 2023-11-07 ยท Modified 2023-11-14
CVSS v3
โ€”
CVSS v4 NEW
โ€”
not yet in upstream
VIR risk
5.5

Description

Moderate: libreoffice security update

Predictions

Exploit likelihood
20%
Patch ETA
โ€”

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

Mitigation details

Source: Debian Security Tracker ยท View original โ†— ยท DFSG

CVE-2023-1183 NameCVE-2023-1183 DescriptionA flaw was found in the Libreoffice package. An attacker can craft an odb containing a "database/script" file with a SCRIPT command where the contents of the file could be written to a new file whose location was determined by the attacker. SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE,โ€ฆ

CVE-2023-1183

NameCVE-2023-1183
DescriptionA flaw was found in the Libreoffice package. An attacker can craft an odb containing a "database/script" file with a SCRIPT command where the contents of the file could be written to a new file whose location was determined by the attacker.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
ReferencesDLA-3467-1, DLA-3468-1, DSA-5436-1, DSA-5437-1, DSA-5995-1

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
hsqldb (PTS)bullseye (security), bullseye2.5.1-1+deb11u2fixed
bookworm, bookworm (security)2.7.1-1+deb12u1fixed
forky, sid, trixie2.7.4-1fixed
hsqldb1.8.0 (PTS)bullseye (security), bullseye1.8.0.10+dfsg-10+deb11u1fixed
bookworm, bookworm (security)1.8.0.10+dfsg-11+deb12u1fixed
trixie (security), trixie1.8.0.10+dfsg-12.1+deb13u1fixed
forky, sid1.8.0.10+dfsg2-2fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
hsqldbsourcebuster2.4.1-2+deb10u2DLA-3467-1
hsqldbsourcebullseye2.5.1-1+deb11u2DSA-5437-1
hsqldbsourcebookworm2.7.1-1+deb12u1DSA-5437-1
hsqldbsource(unstable)2.7.2-1
hsqldb1.8.0sourcebuster1.8.0.10+dfsg-10+deb10u1DLA-3468-1
hsqldb1.8.0sourcebullseye1.8.0.10+dfsg-10+deb11u1DSA-5436-1
hsqldb1.8.0sourcebookworm1.8.0.10+dfsg-11+deb12u1DSA-5436-1
hsqldb1.8.0sourcetrixie1.8.0.10+dfsg-12.1+deb13u1DSA-5995-1
hsqldb1.8.0source(unstable)1.8.0.10+dfsg-14

Notes

https://www.libreoffice.org/about-us/security/advisories/cve-2023-1183/
https://gerrit.libreoffice.org/c/core/+/146905
https://sourceforge.net/p/hsqldb/svn/6639/

Home - Debian Security - Source (Git)

Apply commands

text fix
Notes
https://www.libreoffice.org/about-us/security/advisories/cve-2023-1183/https://gerrit.libreoffice.org/c/core/+/146905https://sourceforge.net/p/hsqldb/svn/6639/

OS impact

suse SUSE Affected 1 release
VersionStatusFixed in
โ€” Affected โ€”
almalinux AlmaLinux Fixed 1 release
VersionStatusFixed in
9 Fixed autocorr-it-7.1.8.1-11.el9.alma.noarch.rpm
debian Debian Fixed 5 releases
VersionStatusFixed in
trixie Fixed 2.7.2-1
sid Fixed 2.7.2-1
forky Fixed 2.7.2-1
bullseye Fixed 2.5.1-1+deb11u2
bookworm Fixed 2.7.1-1+deb12u1
redhat Red Hat Fixed 2 releases
VersionStatusFixed in
9 Fixed โ€”
8 Fixed โ€”

References

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.