Bug 125686 - Code execution in document without user prompt
Summary: Code execution in document without user prompt
Status: RESOLVED FIXED
Alias: None
Product: LibreOffice
Classification: Unclassified
Component: LibreOffice (show other bugs)
Version:
(earliest affected)
6.2.4.2 release
Hardware: All All
: medium normal
Assignee: Caolán McNamara
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2019-06-04 15:03 UTC by Nils Emmerich
Modified: 2019-09-04 11:25 UTC (History)
2 users (show)

See Also:
Crash report or crash signature:


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Nils Emmerich 2019-06-04 15:03:08 UTC
Description:
It is possible to get code execution in a document without the user getting a prompt with the highest macro settings

Steps to Reproduce:
Open a specific document I'm not going to attach here

Actual Results:
calc.exe opens

Expected Results:
Showing some sort of error or prompt


Reproducible: Always


User Profile Reset: No



Additional Info:
Version: 6.2.4.2 (x64)
Build ID: 2412653d852ce75f65fbfa83fb7e7b669a126d64
CPU threads: 4; OS: Windows 10.0; UI render: default; VCL: win; 
Locale: en-US (en_US); UI-Language: en-US
Calc: threaded
Comment 1 raal 2019-06-04 16:25:06 UTC
Hello,

Thank you for filing the bug. Please send us a sample document, as this makes it easier for us to verify the bug. 
I have set the bug's status to 'NEEDINFO', so please do change it back to 'UNCONFIRMED' once you have attached a document.
(Please note that the attachment will be public, remove any sensitive information before attaching it.)
How can I eliminate confidential data from a sample document?
https://wiki.documentfoundation.org/QA/FAQ#How_can_I_eliminate_confidential_data_from_a_sample_document.3F
Thank you
Comment 2 raal 2019-06-04 16:35:46 UTC
Maybe security problem: https://www.libreoffice.org/about-us/security/  see Incident Response Procedure
Comment 3 Caolán McNamara 2019-09-04 11:25:02 UTC
Addressed by CVE-2019-9848