4.3

CVE-2015-4551

LibreOffice before 4.4.5 and Apache OpenOffice before 4.1.2 uses the stored LinkUpdateMode configuration information in OpenDocument Format files and templates when handling links, which might allow remote attackers to obtain sensitive information via a crafted document, which embeds data from local files into (1) Calc or (2) Writer.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Libreoffice ≫ Libreoffice Version <= 4.4.4
Canonical ≫ Ubuntu Linux Version 12.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 14.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 15.04
Debian ≫ Debian Linux Version 7.0
Debian ≫ Debian Linux Version 8.0
Apache ≫ Openoffice Version <= 4.1.1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 13.83% 0.96
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:P/I:N/A:N
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.html
Third Party Advisory
https://security.gentoo.org/glsa/201603-05
Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2015-2619.html
Third Party Advisory
http://www.debian.org/security/2015/dsa-3394
Third Party Advisory
http://www.libreoffice.org/about-us/security/advisories/cve-2015-4551/
Vendor Advisory
http://www.openoffice.org/security/cves/CVE-2015-4551.html
Vendor Advisory
http://www.securityfocus.com/bid/77486
Third Party Advisory
Broken Link
VDB Entry
http://www.securitytracker.com/id/1034085
Third Party Advisory
VDB Entry
http://www.securitytracker.com/id/1034091
Third Party Advisory
VDB Entry
http://www.ubuntu.com/usn/USN-2793-1
Third Party Advisory
https://security.gentoo.org/glsa/201611-03
Third Party Advisory