LibreOffice´úÂëÖ´Ðзì϶°²È«¹«¸æ

°ä²¼¹¦·ò 2019-07-29

¡ô ·ì϶±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-9848£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨


¡ô Ó°Ïì°æ±¾


ÊÜÓ°ÏìµÄ°æ±¾


LibreOffice 6.2.5¼°Ö®Ç°°æ±¾


¡ô ·ì϶¸ÅÊö


LibreOfficeÊÇÓÉThe Document Foundation¿ª·¢µÄMS OfficeµÄ¿ªÔ´°ì¹«Ì×¼þ´úÌæÆ·£¬Óë.doc£¬.docx£¬.xls£¬.xlsx£¬.ppt£¬.pptxÎļþ¼æÈݲ¢Ö§³ÖËùÓвÙ×÷ϵͳƽ̨¡£


×êÑÐÈËÔ±ÔÚLibreOfficeÖз¢ÏÖÁËÒ»¸ö´úÂëÖ´Ðзì϶£¬¸Ã·ì϶ÔÊÐí¹¥»÷Õß¾²Ä¬Ö´ÐÐËÁÒâpythonºÅÁ¶ø²»»á·¢³öÖÒ¸æÒÔÀûÓÃÒ×Êܹ¥»÷µÄϵͳ¡£


ĬÈÏÇé¿öÏ£¬LibreOfficeËæ¸½LibreLogo£¨PythonÚ¹ÊÍÆ÷£©£¬ÕâÊÇÒ»¸öºê¿É±à³ÌÒÆ¶¯ÎÚ¹êʸÁ¿Í¼ÐÎÀ´Ö´ÐÐ×Ô½ç˵¾ç±¾´úÂ룬ÄÚ²¿×ª»»python´úÂë²¢Ö´ÐС£¹Ø¼üÃýÎóÕýºÃ´æÔÚÓÚLibreLogoÖУ¬ÆäÖдúÂë²»Äܺܺõط­Ò룬ֻÊÇÌṩpython´úÂ룬ÓÉÓھ籾´úÂëʱʱÔÚ·­ÒëºóÌìÉúÒ»ÑùµÄ´úÂë¡£


LibreOffice½¨²¹ÁË´Ë·ì϶£¬µ«ÔÚTwitterÉÏÓÐÒ»¸öÃû½ÐAlexµÄ×êÑÐÔ±Ðû³ÆËû³É¹¦ÈƹýÁËLibreOffice 6.2.5ÖÐCVE-2019-9848µÄ½¨¸´·¨Ê½¡£


¡ô ·ì϶ÑéÖ¤


POC£ºhttps://insinuator.net/2019/07/libreoffice-a-python-interpreter-code-execution-vulnerability-cve-2019-9848/¡£


¡ô ½¨¸´½¨Òé


ÓÉÓÚAlex»ã±¨ÁËÐÂÃýÎó£¬LibreOfficeÍŶÓÈÔÔÚÖÂÁ¦½¨¸´·ì϶£¬Ä¿Ç°½¨ÒéÔÚµ±Ç°°æ±¾µÄLibreOfficeÖнûÓÃLibreLogo×é¼þ¡£


¡ô ²Î¿¼Á´½Ó


https://gbhackers.com/libreoffice/