4.3
CVE-2015-4551
- EPSS 13.83%
- Veröffentlicht 10.11.2015 17:59:00
- Zuletzt bearbeitet 06.05.2026 22:30:45
- Erkennungen
LibreOffice before 4.4.5 and Apache OpenOffice before 4.1.2 uses the stored LinkUpdateMode configuration information in OpenDocument Format files and templates when handling links, which might allow remote attackers to obtain sensitive information via a crafted document, which embeds data from local files into (1) Calc or (2) Writer.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Libreoffice ≫ Libreoffice Version <= 4.4.4
Canonical ≫ Ubuntu Linux Version 12.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 14.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 15.04
Debian ≫ Debian Linux Version 7.0
Debian ≫ Debian Linux Version 8.0
Apache ≫ Openoffice Version <= 4.1.1
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 13.83% | 0.96 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 4.3 | 8.6 | 2.9 |
AV:N/AC:M/Au:N/C:P/I:N/A:N
|
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.html
https://security.gentoo.org/glsa/201603-05
http://rhn.redhat.com/errata/RHSA-2015-2619.html
http://www.debian.org/security/2015/dsa-3394
http://www.libreoffice.org/about-us/security/advisories/cve-2015-4551/
http://www.openoffice.org/security/cves/CVE-2015-4551.html
http://www.securityfocus.com/bid/77486
http://www.securitytracker.com/id/1034085
http://www.securitytracker.com/id/1034091
http://www.ubuntu.com/usn/USN-2793-1
https://security.gentoo.org/glsa/201611-03