{"id":36775,"date":"2019-10-31T22:13:44","date_gmt":"2019-10-31T19:13:44","guid":{"rendered":"https:\/\/prohoster.info\/blog\/uyazvimost-v-libreoffice-pozvolyayushhaya-vypolnit-kod-pri-otkrytii-vredonosnyh-dokumentov\/"},"modified":"2019-10-31T22:13:44","modified_gmt":"2019-10-31T19:13:44","slug":"uyazvimost-v-libreoffice-pozvolyayushhaya-vypolnit-kod-pri-otkrytii-vredonosnyh-dokumentov","status":"publish","type":"post","link":"https:\/\/prohoster.info\/ro\/blog\/news\/uyazvimost-v-libreoffice-pozvolyayushhaya-vypolnit-kod-pri-otkrytii-vredonosnyh-dokumentov","title":{"rendered":"O vulnerabilitate \u00een LibreOffice care permite executarea codului la deschiderea documentelor mali\u021bioase","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>\u00cen pachetul office LibreOffice <noindex><a rel=\"nofollow\" href=\"https:\/\/insinuator.net\/2019\/07\/libreoffice-a-python-interpreter-code-execution-vulnerability-cve-2019-9848\/\">a fost identificat\u0103<\/a><\/noindex> vulnerabilitate (<noindex><a rel=\"nofollow\" href=\"https:\/\/www.libreoffice.org\/about-us\/security\/advisories\/cve-2019-9848\">CVE-2019-9848<\/a><\/noindex>), care poate fi folosit\u0103 pentru a executa cod arbitrar la deschiderea documentelor preg\u0103tite de un atacator. <\/p>\n<p>Vulnerabilitatea este cauzat\u0103 de faptul c\u0103 componenta LibreLogo, destinat\u0103 instruirii \u00een programare \u0219i inser\u0103rii de desene vectoriale, traduce opera\u021biunile sale \u00een cod Python. Av\u00e2nd capacitatea de a executa instruc\u021biuni LibreLogo, un atacator poate ob\u021bine execu\u021bia oric\u0103rui cod Python \u00een contextul sesiunii curente a utilizatorului, folosind comanda \u201erun\u201d furnizat\u0103 \u00een LibreLogo. Din Python, prin func\u021bia system(), se pot, la r\u00e2ndul s\u0103u, apela comenzi sistemice arbitrare.<\/p>\n<p>LibreLogo este o component\u0103 op\u021bional\u0103, dar \u00een LibreOffice sunt oferite \u00een mod implicit macrocomenzi care permit apelarea LibreLogo \u0219i nu necesit\u0103 confirmarea execu\u021biei opera\u021biunii, nici nu afi\u0219eaz\u0103 un avertisment, chiar \u0219i atunci c\u00e2nd este activat modul de protec\u021bie maxim\u0103 a macrocomenzilor (selectarea nivelului \u201eVery High\u201d).<br \/>\nPentru atac, un astfel de macro poate fi asociat cu un eveniment care se declan\u0219eaz\u0103, de exemplu, atunci c\u00e2nd cursorul mouse-ului este plasat peste o anumit\u0103 zon\u0103 sau c\u00e2nd se activeaz\u0103 focusul de input pe document (evenimentul onFocus). A\u0219adar, la deschiderea unui document preg\u0103tit de atacator, poate fi ob\u021binut\u0103 o executare ascuns\u0103 a codului Python, f\u0103r\u0103 ca utilizatorul s\u0103 observa. De exemplu, \u00een exemplul de exploit demonstrat, la deschiderea documentului, f\u0103r\u0103 un avertisment, se lanseaz\u0103 calculatorul sistemului.<br \/>\n<center><img decoding=\"async\" alt=\"O vulnerabilitate \u00een LibreOffice care permite executarea codului la deschiderea documentelor mali\u021bioase\" src=\"\/wp-content\/uploads\/2019\/08\/0fec54fd44a32fd9940cc833f8490b21.png\" style=\"display:block;margin: 0 auto;\" \/><\/center><\/p>\n<p>Vulnerabilitatea a fost corectat\u0103 f\u0103r\u0103 o publicitate excesiv\u0103 \u00een actualizarea LibreOffice 6.2.5, lansat\u0103 pe 1 iulie, dar, a\u0219a cum s-a dovedit, problema nu a fost remediate complet (a fost blocat\u0103 doar apelarea LibreLogo din macrocomenzi) \u0219i <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/rapid7\/metasploit-framework\/pull\/12147\">r\u0103m\u00e2n necorectate<\/a><\/noindex> anumite alte vectori pentru realizarea atacului. \u00cen plus, problema nu este rezolvat\u0103 \u00een versiunea 6.1.6, recomandat\u0103 pentru utilizatorii de corpora\u021bii. Corectarea complet\u0103 a vulnerabilit\u0103\u021bii este planificat\u0103 pentru versiunea LibreOffice 6.3, a\u0219teptat\u0103 s\u0103pt\u0103m\u00e2na viitoare. P\u00e2n\u0103 la lansarea actualiz\u0103rii complete, utilizatorilor li se recomand\u0103 s\u0103 dezactiveze explicit componenta LibreLogo, care este disponibil\u0103 \u00een mod implicit \u00een multe distribu\u021bii. Par\u021bial, vulnerabilitatea a fost corectat\u0103 \u00een <noindex><a rel=\"nofollow\" href=\"https:\/\/security-tracker.debian.org\/tracker\/CVE-2019-9848\">Debian<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/bodhi.fedoraproject.org\/updates\/?releases=F30&#038;type=security\">Fedora<\/a><\/noindex>,  <noindex><a rel=\"nofollow\" href=\"https:\/\/bugzilla.novell.com\/show_bug.cgi?id=CVE-2019-9848\">SUSE\/openSUSE<\/a><\/noindex> \u0219i <noindex><a rel=\"nofollow\" href=\"https:\/\/usn.ubuntu.com\/4063-1\/\">Ubuntu<\/a><\/noindex>.<\/p>\n<p><noindex><a rel=\"nofollow\" name=\"link\"><\/a><\/noindex><\/p>\n<p>Sursa: <a \ncontent=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=51214\">opennet.ro<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0412 \u043e\u0444\u0438\u0441\u043d\u043e\u043c \u043f\u0430\u043a\u0435\u0442\u0435 LibreOffice \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2019-9848), \u043a\u043e\u0442\u043e\u0440\u0443\u044e \u043c\u043e\u0436\u043d\u043e \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u044c \u0434\u043b\u044f \u0432\u044b\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u044f \u043f\u0440\u043e\u0438\u0437\u0432\u043e\u043b\u044c\u043d\u043e\u0433\u043e \u043a\u043e\u0434\u0430 \u043f\u0440\u0438 \u043e\u0442\u043a\u0440\u044b\u0442\u0438\u0438 \u0434\u043e\u043a\u0443\u043c\u0435\u043d\u0442\u043e\u0432, \u043f\u043e\u0434\u0433\u043e\u0442\u043e\u0432\u043b\u0435\u043d\u043d\u044b\u0445 \u0437\u043b\u043e\u0443\u043c\u044b\u0448\u043b\u0435\u043d\u043d\u0438\u043a\u043e\u043c. \u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432\u044b\u0437\u0432\u0430\u043d\u0430 \u0442\u0435\u043c, \u0447\u0442\u043e \u043a\u043e\u043c\u043f\u043e\u043d\u0435\u043d\u0442 LibreLogo, \u043f\u0440\u0435\u0434\u043d\u0430\u0437\u043d\u0430\u0447\u0435\u043d\u043d\u044b\u0439 \u0434\u043b\u044f \u043e\u0431\u0443\u0447\u0435\u043d\u0438\u044f \u043f\u0440\u043e\u0433\u0440\u0430\u043c\u043c\u0438\u0440\u043e\u0432\u0430\u043d\u0438\u044e \u0438 \u0432\u0441\u0442\u0430\u0432\u043a\u0438 \u0432\u0435\u043a\u0442\u043e\u0440\u043d\u044b\u0445 \u0440\u0438\u0441\u0443\u043d\u043a\u043e\u0432, \u0442\u0440\u0430\u043d\u0441\u043b\u0438\u0440\u0443\u0435\u0442 \u0441\u0432\u043e\u0438 \u043e\u043f\u0435\u0440\u0430\u0446\u0438\u0438 \u0432 \u043a\u043e\u0434 \u043d\u0430 \u044f\u0437\u044b\u043a\u0435 Python. \u0418\u043c\u0435\u044f \u0432\u043e\u0437\u043c\u043e\u0436\u043d\u043e\u0441\u0442\u044c \u0432\u044b\u043f\u043e\u043b\u043d\u0438\u0442\u044c \u0438\u043d\u0441\u0442\u0440\u0443\u043a\u0446\u0438\u0438 LibreLogo \u0437\u043b\u043e\u0443\u043c\u044b\u0448\u043b\u0435\u043d\u043d\u0438\u043a \u043c\u043e\u0436\u0435\u0442 \u0434\u043e\u0431\u0438\u0442\u044c\u0441\u044f \u0432\u044b\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u044f \u043b\u044e\u0431\u043e\u0433\u043e \u043a\u043e\u0434\u0430 \u043d\u0430 \u044f\u0437\u044b\u043a\u0435 Python [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":27546,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-36775","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0412 \u043e\u0444\u0438\u0441\u043d\u043e\u043c \u043f\u0430\u043a\u0435\u0442\u0435 LibreOffice \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/ro\/blog\/news\/uyazvimost-v-libreoffice-pozvolyayushhaya-vypolnit-kod-pri-otkrytii-vredonosnyh-dokumentov\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2\" \/>\n\t\t<meta property=\"og:locale\" content=\"ro_RO\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432 LibreOffice, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u0432\u044b\u043f\u043e\u043b\u043d\u0438\u0442\u044c \u043a\u043e\u0434 \u043f\u0440\u0438 \u043e\u0442\u043a\u0440\u044b\u0442\u0438\u0438 \u0432\u0440\u0435\u0434\u043e\u043d\u043e\u0441\u043d\u044b\u0445 \u0434\u043e\u043a\u0443\u043c\u0435\u043d\u0442\u043e\u0432 | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0412 \u043e\u0444\u0438\u0441\u043d\u043e\u043c \u043f\u0430\u043a\u0435\u0442\u0435 LibreOffice \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/ro\/blog\/news\/uyazvimost-v-libreoffice-pozvolyayushhaya-vypolnit-kod-pri-otkrytii-vredonosnyh-dokumentov\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2019-10-31T19:13:44+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2019-10-31T19:13:44+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Vulnerabilitate \u00een LibreOffice care permite executarea de cod la deschiderea documentelor mali\u021bioase | ProHoster","description":"S-a descoperit o vulnerabilitate \u00een pachetul office LibreOffice.","canonical_url":"https:\/\/prohoster.info\/ro\/blog\/news\/uyazvimost-v-libreoffice-pozvolyayushhaya-vypolnit-kod-pri-otkrytii-vredonosnyh-dokumentov","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"ro_RO","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432 LibreOffice, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u0432\u044b\u043f\u043e\u043b\u043d\u0438\u0442\u044c \u043a\u043e\u0434 \u043f\u0440\u0438 \u043e\u0442\u043a\u0440\u044b\u0442\u0438\u0438 \u0432\u0440\u0435\u0434\u043e\u043d\u043e\u0441\u043d\u044b\u0445 \u0434\u043e\u043a\u0443\u043c\u0435\u043d\u0442\u043e\u0432 | ProHoster","og:description":"\u0412 \u043e\u0444\u0438\u0441\u043d\u043e\u043c \u043f\u0430\u043a\u0435\u0442\u0435 LibreOffice \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c.","og:url":"https:\/\/prohoster.info\/ro\/blog\/news\/uyazvimost-v-libreoffice-pozvolyayushhaya-vypolnit-kod-pri-otkrytii-vredonosnyh-dokumentov","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2019-10-31T19:13:44+00:00","article:modified_time":"2019-10-31T19:13:44+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"36775","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":"2026-01-22 04:48:19","breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-03-01 01:39:22","updated":"2026-01-22 04:48:19","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/posts\/36775","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/comments?post=36775"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/posts\/36775\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/media\/27546"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/media?parent=36775"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/categories?post=36775"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/tags?post=36775"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}