Oval Definition:oval:com.ubuntu.xenial:def:201998510000000
Revision Date:2019-08-15Version:1
Title:CVE-2019-9851 on Ubuntu 16.04 LTS (xenial) - medium.
Description:LibreOffice is typically bundled with LibreLogo, a programmable turtle vector graphics script, which can execute arbitrary python commands contained with the document it is launched from. Protection was added, to address CVE-2019-9848, to block calling LibreLogo from document event script handers, e.g. mouse over. However LibreOffice also has a separate feature where documents can specify that pre-installed scripts can be executed on various global script events such as document-open, etc. In the fixed versions, global script event handlers are validated equivalently to document script event handlers. This issue affects: Document Foundation LibreOffice versions prior to 6.2.6.
Family:unixClass:vulnerability
Status:Reference(s):CVE-2019-9851
Platform(s):Ubuntu 16.04 LTS
Product(s):
Definition Synopsis
  • Ubuntu 16.04 LTS (xenial) is installed.
  • AND libreoffice package in xenial was vulnerable but has been fixed (note: '1:5.1.6~rc2-0ubuntu1~xenial9').
  • BACK