{"id":36775,"date":"2019-10-31T22:13:44","date_gmt":"2019-10-31T19:13:44","guid":{"rendered":"https:\/\/prohoster.info\/blog\/uyazvimost-v-libreoffice-pozvolyayushhaya-vypolnit-kod-pri-otkrytii-vredonosnyh-dokumentov\/"},"modified":"2019-10-31T22:13:44","modified_gmt":"2019-10-31T19:13:44","slug":"uyazvimost-v-libreoffice-pozvolyayushhaya-vypolnit-kod-pri-otkrytii-vredonosnyh-dokumentov","status":"publish","type":"post","link":"https:\/\/prohoster.info\/fr\/blog\/news\/uyazvimost-v-libreoffice-pozvolyayushhaya-vypolnit-kod-pri-otkrytii-vredonosnyh-dokumentov","title":{"rendered":"Vuln\u00e9rabilit\u00e9 dans LibreOffice permettant d'ex\u00e9cuter du code lors de l'ouverture de documents malveillants","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>Dans la suite bureautique LibreOffice <noindex><a rel=\"nofollow\" href=\"https:\/\/insinuator.net\/2019\/07\/libreoffice-a-python-interpreter-code-execution-vulnerability-cve-2019-9848\/\">une vuln\u00e9rabilit\u00e9 a \u00e9t\u00e9 identifi\u00e9e<\/a><\/noindex> une vuln\u00e9rabilit\u00e9 (<noindex><a rel=\"nofollow\" href=\"https:\/\/www.libreoffice.org\/about-us\/security\/advisories\/cve-2019-9848\">CVE-2019-9848<\/a><\/noindex>), qui peut \u00eatre utilis\u00e9e pour ex\u00e9cuter du code arbitraire lors de l'ouverture de documents pr\u00e9par\u00e9s par un attaquant. <\/p>\n<p>La vuln\u00e9rabilit\u00e9 est due au fait que le composant LibreLogo, con\u00e7u pour l'apprentissage de la programmation et l'insertion de dessins vectoriels, traduit ses op\u00e9rations en code Python. En ayant la possibilit\u00e9 d'ex\u00e9cuter des instructions LibreLogo, un attaquant peut ex\u00e9cuter n'importe quel code Python dans le contexte de la session actuelle de l'utilisateur, en utilisant la commande \u00ab run \u00bb fournie par LibreLogo. \u00c0 partir de Python, on peut, \u00e0 l'aide de la fonction system(), appeler des commandes syst\u00e8mes arbitraires.<\/p>\n<p>LibreLogo est un composant optionnel, mais LibreOffice propose par d\u00e9faut des macros qui permettent d'appeler LibreLogo sans n\u00e9cessiter de confirmation pour leur ex\u00e9cution et sans afficher d'avertissement, m\u00eame lorsque le mode de protection maximale des macros est activ\u00e9 (choix du niveau \u00ab Very High \u00bb).<br \/>\nPour l'attaque, un tel macro peut \u00eatre li\u00e9 \u00e0 un gestionnaire d'\u00e9v\u00e9nements qui se d\u00e9clenche, par exemple, lorsque le curseur de la souris survole une certaine zone ou lorsqu'un champ de saisie est activ\u00e9 dans le document (\u00e9v\u00e9nement onFocus). Ainsi, lors de l'ouverture d'un document pr\u00e9par\u00e9 par l'attaquant, il est possible d'ex\u00e9cuter discr\u00e8tement du code Python, \u00e0 l'insu de l'utilisateur. Par exemple, dans l'exemple d'exploit d\u00e9montr\u00e9, \u00e0 l'ouverture du document, le calculateur syst\u00e8me se lance sans avertissement.<br \/>\n<center><img decoding=\"async\" alt=\"Vuln\u00e9rabilit\u00e9 dans LibreOffice permettant d&#039;ex\u00e9cuter du code lors de l&#039;ouverture de documents malveillants\" src=\"\/wp-content\/uploads\/2019\/08\/0fec54fd44a32fd9940cc833f8490b21.png\" style=\"display:block;margin: 0 auto;\" \/><\/center><\/p>\n<p>La vuln\u00e9rabilit\u00e9 a \u00e9t\u00e9 corrig\u00e9e discr\u00e8tement dans la mise \u00e0 jour de LibreOffice 6.2.5, publi\u00e9e le 1er juillet, mais il s'est av\u00e9r\u00e9 que le probl\u00e8me n'a pas \u00e9t\u00e9 compl\u00e8tement r\u00e9solu (seule l'invocation de LibreLogo depuis des macros a \u00e9t\u00e9 bloqu\u00e9e) et <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/rapid7\/metasploit-framework\/pull\/12147\">certains autres vecteurs d'attaque restent non corrig\u00e9s.<\/a><\/noindex> De plus, le probl\u00e8me n'est pas r\u00e9solu dans la version 6.1.6, recommand\u00e9e pour les utilisateurs d'entreprise. La vuln\u00e9rabilit\u00e9 devrait \u00eatre compl\u00e8tement corrig\u00e9e dans la version LibreOffice 6.3, attendue la semaine prochaine. En attendant la publication de la mise \u00e0 jour compl\u00e8te, il est recommand\u00e9 aux utilisateurs de d\u00e9sactiver explicitement le composant LibreLogo, qui est par d\u00e9faut disponible dans de nombreuses distributions. La vuln\u00e9rabilit\u00e9 a \u00e9t\u00e9 partiellement corrig\u00e9e dans <noindex><a rel=\"nofollow\" href=\"https:\/\/security-tracker.debian.org\/tracker\/CVE-2019-9848\">Debian<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/bodhi.fedoraproject.org\/updates\/?releases=F30&#038;type=security\">Fedora<\/a><\/noindex>,  <noindex><a rel=\"nofollow\" href=\"https:\/\/bugzilla.novell.com\/show_bug.cgi?id=CVE-2019-9848\">SUSE\/openSUSE<\/a><\/noindex> et <noindex><a rel=\"nofollow\" href=\"https:\/\/usn.ubuntu.com\/4063-1\/\">Ubuntu<\/a><\/noindex>.<\/p>\n<p><noindex><a rel=\"nofollow\" name=\"link\"><\/a><\/noindex><\/p>\n<p>Source : <a \ncontent=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=51214\">opennet.ru<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0412 \u043e\u0444\u0438\u0441\u043d\u043e\u043c \u043f\u0430\u043a\u0435\u0442\u0435 LibreOffice \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2019-9848), \u043a\u043e\u0442\u043e\u0440\u0443\u044e \u043c\u043e\u0436\u043d\u043e \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u044c \u0434\u043b\u044f \u0432\u044b\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u044f \u043f\u0440\u043e\u0438\u0437\u0432\u043e\u043b\u044c\u043d\u043e\u0433\u043e \u043a\u043e\u0434\u0430 \u043f\u0440\u0438 \u043e\u0442\u043a\u0440\u044b\u0442\u0438\u0438 \u0434\u043e\u043a\u0443\u043c\u0435\u043d\u0442\u043e\u0432, \u043f\u043e\u0434\u0433\u043e\u0442\u043e\u0432\u043b\u0435\u043d\u043d\u044b\u0445 \u0437\u043b\u043e\u0443\u043c\u044b\u0448\u043b\u0435\u043d\u043d\u0438\u043a\u043e\u043c. \u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432\u044b\u0437\u0432\u0430\u043d\u0430 \u0442\u0435\u043c, \u0447\u0442\u043e \u043a\u043e\u043c\u043f\u043e\u043d\u0435\u043d\u0442 LibreLogo, \u043f\u0440\u0435\u0434\u043d\u0430\u0437\u043d\u0430\u0447\u0435\u043d\u043d\u044b\u0439 \u0434\u043b\u044f \u043e\u0431\u0443\u0447\u0435\u043d\u0438\u044f \u043f\u0440\u043e\u0433\u0440\u0430\u043c\u043c\u0438\u0440\u043e\u0432\u0430\u043d\u0438\u044e \u0438 \u0432\u0441\u0442\u0430\u0432\u043a\u0438 \u0432\u0435\u043a\u0442\u043e\u0440\u043d\u044b\u0445 \u0440\u0438\u0441\u0443\u043d\u043a\u043e\u0432, \u0442\u0440\u0430\u043d\u0441\u043b\u0438\u0440\u0443\u0435\u0442 \u0441\u0432\u043e\u0438 \u043e\u043f\u0435\u0440\u0430\u0446\u0438\u0438 \u0432 \u043a\u043e\u0434 \u043d\u0430 \u044f\u0437\u044b\u043a\u0435 Python. \u0418\u043c\u0435\u044f \u0432\u043e\u0437\u043c\u043e\u0436\u043d\u043e\u0441\u0442\u044c \u0432\u044b\u043f\u043e\u043b\u043d\u0438\u0442\u044c \u0438\u043d\u0441\u0442\u0440\u0443\u043a\u0446\u0438\u0438 LibreLogo \u0437\u043b\u043e\u0443\u043c\u044b\u0448\u043b\u0435\u043d\u043d\u0438\u043a \u043c\u043e\u0436\u0435\u0442 \u0434\u043e\u0431\u0438\u0442\u044c\u0441\u044f \u0432\u044b\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u044f \u043b\u044e\u0431\u043e\u0433\u043e \u043a\u043e\u0434\u0430 \u043d\u0430 \u044f\u0437\u044b\u043a\u0435 Python [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":27546,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-36775","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0412 \u043e\u0444\u0438\u0441\u043d\u043e\u043c \u043f\u0430\u043a\u0435\u0442\u0435 LibreOffice \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/fr\/blog\/news\/uyazvimost-v-libreoffice-pozvolyayushhaya-vypolnit-kod-pri-otkrytii-vredonosnyh-dokumentov\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2\" \/>\n\t\t<meta property=\"og:locale\" content=\"fr_FR\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432 LibreOffice, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u0432\u044b\u043f\u043e\u043b\u043d\u0438\u0442\u044c \u043a\u043e\u0434 \u043f\u0440\u0438 \u043e\u0442\u043a\u0440\u044b\u0442\u0438\u0438 \u0432\u0440\u0435\u0434\u043e\u043d\u043e\u0441\u043d\u044b\u0445 \u0434\u043e\u043a\u0443\u043c\u0435\u043d\u0442\u043e\u0432 | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0412 \u043e\u0444\u0438\u0441\u043d\u043e\u043c \u043f\u0430\u043a\u0435\u0442\u0435 LibreOffice \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/fr\/blog\/news\/uyazvimost-v-libreoffice-pozvolyayushhaya-vypolnit-kod-pri-otkrytii-vredonosnyh-dokumentov\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2019-10-31T19:13:44+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2019-10-31T19:13:44+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Vuln\u00e9rabilit\u00e9 dans LibreOffice permettant d'ex\u00e9cuter du code lors de l'ouverture de documents malveillants | ProHoster","description":"Une vuln\u00e9rabilit\u00e9 a \u00e9t\u00e9 d\u00e9couverte dans la suite bureautique LibreOffice.","canonical_url":"https:\/\/prohoster.info\/fr\/blog\/news\/uyazvimost-v-libreoffice-pozvolyayushhaya-vypolnit-kod-pri-otkrytii-vredonosnyh-dokumentov","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"fr_FR","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432 LibreOffice, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u0432\u044b\u043f\u043e\u043b\u043d\u0438\u0442\u044c \u043a\u043e\u0434 \u043f\u0440\u0438 \u043e\u0442\u043a\u0440\u044b\u0442\u0438\u0438 \u0432\u0440\u0435\u0434\u043e\u043d\u043e\u0441\u043d\u044b\u0445 \u0434\u043e\u043a\u0443\u043c\u0435\u043d\u0442\u043e\u0432 | ProHoster","og:description":"\u0412 \u043e\u0444\u0438\u0441\u043d\u043e\u043c \u043f\u0430\u043a\u0435\u0442\u0435 LibreOffice \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c.","og:url":"https:\/\/prohoster.info\/fr\/blog\/news\/uyazvimost-v-libreoffice-pozvolyayushhaya-vypolnit-kod-pri-otkrytii-vredonosnyh-dokumentov","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2019-10-31T19:13:44+00:00","article:modified_time":"2019-10-31T19:13:44+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"36775","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":"2026-01-22 04:48:19","breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-03-01 01:39:22","updated":"2026-01-22 04:48:19","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/posts\/36775","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/comments?post=36775"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/posts\/36775\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/media\/27546"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/media?parent=36775"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/categories?post=36775"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/tags?post=36775"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}