CVE-2023-1183 Details
Description
A flaw was found in the Libreoffice package. An attacker can craft an odb containing a "database/script" file with a SCRIPT command where the contents of the file could be written to a new file whose location was determined by the attacker.
An arbitrary file write vulnerability has been identified in Apache OpenOffice and LibreOffice. This issue arises in the Base application when a crafted ODB file is opened. The ODB file can contain a 'database/script' file with a SCRIPT command that directs the application to write the script's contents to a file location specified by the attacker. This vulnerability affects Apache OpenOffice through version 4.1.14 and all versions of LibreOffice prior to 7.4.6 and 7.5.1.
Users can upgrade to Apache OpenOffice versions 4.1.15 or later, or to LibreOffice versions 7.4.6, 7.5.1, 25.8.5, or 26.2.1.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2023-1183 | CVE | Third Party Advisory |
| https://bugzilla.redhat.com/show_bug.cgi?id=2208506 | CVE | Issue TrackingThird Party Advisory |
| https://www.libreoffice.org/about-us/security/advisories/cve-2023-1183/ | CVE | PatchVendor Advisory |
| http://www.openwall.com/lists/oss-security/2023/12/28/4 | CVE | |
| http://www.openwall.com/lists/oss-security/2024/01/03/4 | CVE | |
| https://access.redhat.com/security/cve/CVE-2023-1183 | [email protected] | Third Party Advisory |
| https://bugzilla.redhat.com/show_bug.cgi?id=2208506 | [email protected] | Issue TrackingThird Party Advisory |
| https://www.libreoffice.org/about-us/security/advisories/cve-2023-1183/ | [email protected] | PatchVendor Advisory |
| http://www.openwall.com/lists/oss-security/2023/12/28/4 | [email protected] | |
| http://www.openwall.com/lists/oss-security/2024/01/03/4 | [email protected] |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-22 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | [email protected] |
| CWE-20 | Improper Input Validation | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| libreoffice libreoffice | < 7.4.6 7.5.0 |
CPE
Remediation
| |
| fedoraproject fedora | 38 |
CPE
Remediation
| |
| redhat enterprise linux | 8.0 9.0 |
CPE
Remediation
| |
Change History
7 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Nov 21, 2024 | CVE Modified | CVE |
| May 14, 2024 | CVE Modified | [email protected] |
| Jan 3, 2024 | CVE Modified | [email protected] |
| Dec 29, 2023 | CVE Modified | [email protected] |
| Nov 7, 2023 | CVE Modified | [email protected] |
| Jul 17, 2023 | Initial Analysis | [email protected] |