CVE-2020-12802 describes a vulnerability in LibreOffice versions prior to 6.4.4 where remote graphic links in DOCX documents bypassed the "stealth mode" protection, allowing unauthorized retrieval of remote resources even when this security feature was enabled. This medium-severity vulnerability (CVSS 5.3) has a network attack vector and low complexity, potentially leading to information disclosure (C:L). There is no evidence of active exploitation, publicly available exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 6.4.4CPE matchmatch criteria | cpe:2.3:a:libreoffice:libreoffice:*:*:*:*:*:*:*:* | ||
31CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:31:*:*:*:*:*:*:* | ||
15.1CPE matchmatch criteria | cpe:2.3:o:opensuse:leap:15.1:*:*:*:*:*:*:* | ||
15.2CPE matchmatch criteria | cpe:2.3:o:opensuse:leap:15.2:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
libreoffice: 'stealth mode' remote resource restrictions bypass
Jun 8, 2020remote graphics contained in docx format retrieved in 'stealth mode'
remote graphics contained in docx format retrieved in 'stealth mode'