Vulnerability in LibreOffice allows script execution while working with a document
A vulnerability (CVE-2022-3140) has been identified in the free office suite LibreOffice, allowing for the execution of arbitrary scripts by clicking on a specially crafted link in a document or when triggering a specific event while working with a document. The issue has been resolved in the updates LibreOffice 7.3.6 and 7.4.1. The vulnerability was caused by the addition of support for an additional macro call scheme ‘vnd.libreoffice.command’, specific to LibreOffice. This scheme was included in that […]
