LibreOffice´úÂëÖ´ÐÐÎó²îÇ徲ͨ¸æ

Ðû²¼Ê±¼ä 2019-07-29

¡ô Îó²î±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-9848£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨


¡ô Ó°Ïì°æ±¾


ÊÜÓ°ÏìµÄ°æ±¾


LibreOffice 6.2.5¼°Ö®Ç°°æ±¾


¡ô Îó²î¸ÅÊö


LibreOfficeÊÇÓÉThe Document Foundation¿ª·¢µÄMS OfficeµÄ¿ªÔ´°ì¹«Ì×¼þÌæ»»Æ·£¬£¬£¬£¬£¬Óë.doc£¬£¬£¬£¬£¬.docx£¬£¬£¬£¬£¬.xls£¬£¬£¬£¬£¬.xlsx£¬£¬£¬£¬£¬.ppt£¬£¬£¬£¬£¬.pptxÎļþ¼æÈݲ¢Ö§³ÖËùÓвÙ×÷ϵͳƽ̨¡£¡£¡£¡£¡£¡£


Ñо¿Ö°Ô±ÔÚLibreOfficeÖз¢Ã÷ÁËÒ»¸ö´úÂëÖ´ÐÐÎó²î£¬£¬£¬£¬£¬¸ÃÎó²îÔÊÐí¹¥»÷Õß¾²Ä¬Ö´ÐÐí§ÒâpythonÏÂÁ£¬£¬£¬£¬¶ø²»»á·¢³öÖÒÑÔÒÔʹÓÃÒ×Êܹ¥»÷µÄϵͳ¡£¡£¡£¡£¡£¡£


ĬÈÏÇéÐÎÏ£¬£¬£¬£¬£¬LibreOfficeËæ¸½LibreLogo£¨PythonÚ¹ÊÍÆ÷£©£¬£¬£¬£¬£¬ÕâÊÇÒ»¸öºê¿É±à³ÌÒÆ¶¯ÎÚ¹êʸÁ¿Í¼ÐÎÀ´Ö´ÐÐ×Ô½ç˵¾ç±¾´úÂ룬£¬£¬£¬£¬ÄÚ²¿×ª»»python´úÂë²¢Ö´ÐС£¡£¡£¡£¡£¡£Òªº¦¹ýʧÕýºÃ±£´æÓÚLibreLogoÖУ¬£¬£¬£¬£¬ÆäÖдúÂë²»¿ÉºÜºÃµØ·­Ò룬£¬£¬£¬£¬Ö»ÊÇÌṩpython´úÂ룬£¬£¬£¬£¬ÓÉÓھ籾´úÂë¾­³£ÔÚ·­ÒëºóÌìÉúÏàͬµÄ´úÂë¡£¡£¡£¡£¡£¡£


LibreOfficeÐÞ²¹ÁË´ËÎó²î£¬£¬£¬£¬£¬µ«ÔÚTwitterÉÏÓÐÒ»¸öÃû½ÐAlexµÄÑо¿Ô±Éù³ÆËûÀÖ³ÉÈÆ¹ýÁËLibreOffice 6.2.5ÖÐCVE-2019-9848µÄÐÞ¸´³ÌÐò¡£¡£¡£¡£¡£¡£


¡ô Îó²îÑéÖ¤


POC£ºhttps://insinuator.net/2019/07/libreoffice-a-python-interpreter-code-execution-vulnerability-cve-2019-9848/¡£¡£¡£¡£¡£¡£


¡ô ÐÞ¸´½¨Òé


ÓÉÓÚAlex±¨¸æÁËйýʧ£¬£¬£¬£¬£¬LibreOfficeÍŶÓÈÔÔÚÆð¾¢ÐÞ¸´Îó²î£¬£¬£¬£¬£¬ÏÖÔÚ½¨ÒéÔÚÄ¿½ñ°æ±¾µÄLibreOfficeÖнûÓÃLibreLogo×é¼þ¡£¡£¡£¡£¡£¡£


¡ô ²Î¿¼Á´½Ó


https://gbhackers.com/libreoffice/