LibreOffice´úÂëÖ´ÐÐÎó²îÇ徲ͨ¸æ

Ðû²¼Ê±¼ä 2019-07-29

¡ô Îó²î±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-9848£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨


¡ô Ó°Ïì°æ±¾


ÊÜÓ°ÏìµÄ°æ±¾


LibreOffice 6.2.5¼°Ö®Ç°°æ±¾


¡ô Îó²î¸ÅÊö


LibreOfficeÊÇÓÉThe Document Foundation¿ª·¢µÄMS OfficeµÄ¿ªÔ´°ì¹«Ì×¼þÌæ»»Æ·£¬£¬£¬£¬Óë.doc£¬£¬£¬£¬.docx£¬£¬£¬£¬.xls£¬£¬£¬£¬.xlsx£¬£¬£¬£¬.ppt£¬£¬£¬£¬.pptxÎļþ¼æÈݲ¢Ö§³ÖËùÓвÙ×÷ϵͳƽ̨¡£¡£¡£¡£¡£¡£


Ñо¿Ö°Ô±ÔÚLibreOfficeÖз¢Ã÷ÁËÒ»¸ö´úÂëÖ´ÐÐÎó²î£¬£¬£¬£¬¸ÃÎó²îÔÊÐí¹¥»÷Õß¾²Ä¬Ö´ÐÐí§ÒâpythonÏÂÁ£¬£¬£¬¶ø²»»á·¢³öÖÒÑÔÒÔʹÓÃÒ×Êܹ¥»÷µÄϵͳ¡£¡£¡£¡£¡£¡£


ĬÈÏÇéÐÎÏ£¬£¬£¬£¬LibreOfficeËæ¸½LibreLogo£¨PythonÚ¹ÊÍÆ÷£©£¬£¬£¬£¬ÕâÊÇÒ»¸öºê¿É±à³ÌÒÆ¶¯ÎÚ¹êʸÁ¿Í¼ÐÎÀ´Ö´ÐÐ×Ô½ç˵¾ç±¾´úÂ룬£¬£¬£¬ÄÚ²¿×ª»»python´úÂë²¢Ö´ÐС£¡£¡£¡£¡£¡£Òªº¦¹ýʧÕýºÃ±£´æÓÚLibreLogoÖУ¬£¬£¬£¬ÆäÖдúÂë²»¿ÉºÜºÃµØ·­Ò룬£¬£¬£¬Ö»ÊÇÌṩpython´úÂ룬£¬£¬£¬ÓÉÓھ籾´úÂë¾­³£ÔÚ·­ÒëºóÌìÉúÏàͬµÄ´úÂë¡£¡£¡£¡£¡£¡£


LibreOfficeÐÞ²¹ÁË´ËÎó²î£¬£¬£¬£¬µ«ÔÚTwitterÉÏÓÐÒ»¸öÃû½ÐAlexµÄÑо¿Ô±Éù³ÆËûÀÖ³ÉÈÆ¹ýÁËLibreOffice 6.2.5ÖÐCVE-2019-9848µÄÐÞ¸´³ÌÐò¡£¡£¡£¡£¡£¡£


¡ô Îó²îÑéÖ¤


POC£ºhttps://insinuator.net/2019/07/libreoffice-a-python-interpreter-code-execution-vulnerability-cve-2019-9848/¡£¡£¡£¡£¡£¡£


¡ô ÐÞ¸´½¨Òé


ÓÉÓÚAlex±¨¸æÁËйýʧ£¬£¬£¬£¬LibreOfficeÍŶÓÈÔÔÚÆð¾¢ÐÞ¸´Îó²î£¬£¬£¬£¬ÏÖÔÚ½¨ÒéÔÚÄ¿½ñ°æ±¾µÄLibreOfficeÖнûÓÃLibreLogo×é¼þ¡£¡£¡£¡£¡£¡£


¡ô ²Î¿¼Á´½Ó


https://gbhackers.com/libreoffice/