Ukuba sengozini ku-LibreOffice evumela ukwenziwa kwekhodi lapho uvula amadokhumenti anonya

Ehhovisi le-LibreOffice suite ikhonjiwe ubungozi (I-CVE-2019-9848), engasetshenziswa ukwenza ikhodi engafanele lapho uvula amadokhumenti alungiswe umhlaseli.

Ukuba sengozini kubangelwa ukuthi ingxenye ye-LibreLogo, eklanyelwe ukufundisa ukuhlela nokufaka imidwebo ye-vector, ihumusha ukusebenza kwayo kukhodi yePython. Ngamandla okusebenzisa imiyalo ye-LibreLogo, umhlaseli angabangela noma iyiphi ikhodi ye-Python ukuthi isebenze kumongo weseshini yamanje yomsebenzisi ngokusebenzisa umyalo othi "run" onikezwe ku-LibreLogo. Kusuka ku-Python, usebenzisa uhlelo () umsebenzi, ungakwazi, futhi, ushayele imiyalo yesistimu engafanele.

I-LibreLogo iyisici ozikhethela sona, kodwa i-LibreOffice inikeza ama-macro ngokuzenzakalelayo akuvumela ukuthi ushayele i-LibreLogo futhi ayidingi ukuqinisekiswa kokusebenza futhi ayibonisi isixwayiso, ngisho noma imodi yokuvikela enkulu ivuliwe (ukukhetha izinga elithi "Phezulu Kakhulu" ).
Ukuze uhlasele, ungabophezela i-macro enjalo kusibambi somcimbi esiqaliswayo, isibonelo, lapho ikhesa yegundane izuliswa phezulu endaweni ethile noma uma ukugxila kokokufaka kwenziwa kusebenze kudokhumenti (umcimbi we-onFocus). Ngenxa yalokho, lapho uvula idokhumenti elungiselelwe umhlaseli, kungenzeka ukufeza ukwenziwa okufihliwe kwekhodi yePython, umsebenzisi engazi. Isibonelo, esibonelweni sokuxhaphaza esibonisiwe, lapho uvula idokhumenti, isibali sesistimu siqaliswa ngaphandle kwesixwayiso.

Ukuba sengozini ku-LibreOffice evumela ukwenziwa kwekhodi lapho uvula amadokhumenti anonya

Ukuba sengozini kulungiswe buthule kusibuyekezo se-LibreOffice 6.2.5, esikhishwe ngoJulayi 1, kodwa njengoba kwavela, inkinga ayizange isuswe ngokuphelele (ukushayela i-LibreLogo kuphela kuma-macros kuvinjelwe) futhi hlala ungalungisiwe amanye ama-vector okuhlasela. Ukwengeza, inkinga ayixazululwa ekukhishweni kwe-6.1.6, okunconyelwe abasebenzisi bebhizinisi. Ukuba sengozini kuhlelwe ukuthi kulungiswe ngokuphelele ekukhululweni kwe-LibreOffice 6.3, okulindeleke ngesonto elizayo. Kuze kube yilapho kukhishwa isibuyekezo esigcwele, abasebenzisi bayelulekwa ukuthi bakhubaze ngokusobala ingxenye ye-LibreLogo, etholakala ngokuzenzakalelayo ekusabalaliseni okuningi. Ukuba sengozini kulungisiwe kancane Debian, Fedora, SUSE/openSUSE ΠΈ Ubuntu.

Source: opennet.ru

Engeza amazwana