<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>LibreOffice on Insinuator.net - Bold Statements</title>
    <link>https://insinuator.net/tags/libreoffice/</link>
    <description>Recent content in LibreOffice on Insinuator.net - Bold Statements</description>
    <generator>Hugo</generator>
    <language>en-us</language>
    <lastBuildDate>Fri, 26 Jul 2019 00:00:00 +0000</lastBuildDate>
    <atom:link href="https://insinuator.net/tags/libreoffice/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>LibreOffice – A Python Interpreter (code execution vulnerability CVE-2019-9848)</title>
      <link>https://insinuator.net/2019/07/libreoffice-a-python-interpreter-code-execution-vulnerability-cve-2019-9848/</link>
      <pubDate>Fri, 26 Jul 2019 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2019/07/libreoffice-a-python-interpreter-code-execution-vulnerability-cve-2019-9848/</guid>
      <description>&lt;p&gt;While waiting for a download to complete, I stumbled across an interesting &lt;a href=&#34;https://insert-script.blogspot.com/2019/02/libreoffice-cve-2018-16858-remote-code.html&#34;&gt;blogpost&lt;/a&gt;. The author describes a flaw in LibreOffice that allowed an attacker to execute code. Since this was quite recent, I was interested if my version is vulnerable to this attack and how they fixed it. Thus, I looked at the sources and luckily it was fixed. What I didn’t know before however was, that macros shipped with LibreOffice are executed without prompting the user, even on the highest macro security setting. So, if there would be a system macro from LibreOffice with a bug that allows to execute code, the user would not even get a prompt and the code would be executed right away. Therefor, I started to have a closer look at the source code and found out that exactly this is the case!&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
