LibreOffice before 4.4.5 and Apache OpenOffice before 4.1.2 uses the stored LinkUpdateMode configuration information in OpenDocument Format files and templates when handling links, which might allow remote attackers to obtain sensitive information via a crafted document, which embeds data from local files into (1) Calc or (2) Writer.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
http://www.securitytracker.com/id/1034085 | vdb entry third party advisory |
https://security.gentoo.org/glsa/201611-03 | third party advisory vendor advisory |
http://www.securitytracker.com/id/1034091 | vdb entry third party advisory |
http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.html | third party advisory |
http://rhn.redhat.com/errata/RHSA-2015-2619.html | third party advisory vendor advisory |
http://www.ubuntu.com/usn/USN-2793-1 | third party advisory vendor advisory |
http://www.securityfocus.com/bid/77486 | vdb entry third party advisory broken link |
http://www.libreoffice.org/about-us/security/advisories/cve-2015-4551/ | vendor advisory |
https://security.gentoo.org/glsa/201603-05 | third party advisory vendor advisory |
http://www.openoffice.org/security/cves/CVE-2015-4551.html | vendor advisory |
http://www.debian.org/security/2015/dsa-3394 | third party advisory vendor advisory |