Your submission was sent successfully! Close

You have successfully unsubscribed! Close

Thank you for signing up for our newsletter!
In these regular emails you will find the latest updates about Ubuntu and upcoming events where you can meet our team.Close

CVE-2022-26307

Published: 25 July 2022

LibreOffice supports the storage of passwords for web connections in the user’s configuration database. The stored passwords are encrypted with a single master key provided by the user. A flaw in LibreOffice existed where master key was poorly encoded resulting in weakening its entropy from 128 to 43 bits making the stored passwords vulerable to a brute force attack if an attacker has access to the users stored config. This issue affects: The Document Foundation LibreOffice 7.2 versions prior to 7.2.7; 7.3 versions prior to 7.3.3.

Priority

Medium

Cvss 3 Severity Score

8.8

Score breakdown

Status

Package Release Status
libreoffice
Launchpad, Ubuntu, Debian
bionic
Released (1:6.0.7-0ubuntu0.18.04.12)
focal
Released (1:6.4.7-0ubuntu0.20.04.5)
jammy Not vulnerable
(1:7.3.3-0ubuntu0.22.04.1)
kinetic Not vulnerable

lunar Not vulnerable

trusty Ignored
(end of standard support)
upstream
Released (1:7.3.3~rc1-2)
xenial Ignored
(end of standard support)
Patches:
upstream: https://github.com/LibreOffice/core/commit/e890f54dbac57f3ab5acf4fbd31222095d3e8ab6
upstream: https://github.com/LibreOffice/core/commit/c5d01b11db3c83cb4a89d3b388d78e20dd3990b5
upstream: https://github.com/LibreOffice/core/commit/74e1b3f855c7f0349577681601dd1eb11917dd06
upstream: https://github.com/LibreOffice/core/commit/7e35d53f51bb89ed3cea5f946214afb7d81e1b1e
upstream: https://github.com/LibreOffice/core/commit/df05d27336927373bf83664a90156fbe505fc546
upstream: https://github.com/LibreOffice/core/commit/c17ba8306704d6d428d673fb0079c4276f0bc256
upstream: https://github.com/LibreOffice/core/commit/cedd8063fed50cfd75fa3c69c4c87e2ae79b944d

Severity score breakdown

Parameter Value
Base score 8.8
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Scope Unchanged
Confidentiality High
Integrity impact High
Availability impact High
Vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H