¡¾Â©¶´Í¨¸æ¡¿LibreOffice 7Ô¶à¸öÄþ¾²Â©¶´

Ðû²¼Ê±¼ä 2022-07-29

0x00 ©¶´¸ÅÊö

2022Äê7ÔÂ25ÈÕ £¬LibreOfficeÐû²¼Äþ¾²Í¨¸æ £¬ÐÞ¸´ÁËLibreOfficeÈí¼þÖеĶà¸öÄþ¾²Â©¶´ £¬ÕâЩ©¶´¿ÉÄܵ¼ÖÂÐÅϢй¶»ò´úÂëÖ´ÐС£

 

0x01 ©¶´ÏêÇé

LibreOfficeÊÇÒ»¿îÃâ·ÑÇÒ¹¦Ð§Ç¿´óµÄ°ì¹«Ì×¼þ £¬ËüÊÇOpenOffice.org°ì¹«Ì×¼þÑÜÉú°æ¡£

LibreOffice½üÆÚÐÞ¸´µÄ3¸ö©¶´ÈçÏ£º

CVE-2022-26306£ºLibreOffice¼ÓÃÜÄþ¾²Â©¶´

LibreOffice Ö§³Ö½« Web Á¬½ÓµÄÃÜÂë´æ´¢ÔÚÓû§µÄÅäÖÃÊý¾Ý¿âÖÐ £¬´æ´¢µÄÃÜÂëʹÓÃÓû§ÌṩµÄµ¥¸öÖ÷ÃÜÔ¿½øÐмÓÃÜ¡£ÔÚÊÜÓ°ÏìµÄLibreOffic°æ±¾ÖÐ £¬ÓÉÓÚ¼ÓÃÜËùÐèµÄ³õʼ»¯ÏòÁ¿Ê¼ÖÕÏàͬ £¬µ¼Ö¼ÓÃÜÄþ¾²ÐÔ±»Ï÷Èõ £¬Äܹ»·ÃÎÊÓû§ÅäÖÃÊý¾ÝµÄ¶ñÒâÓû§¿ÉÒÔÔÚ²»ÖªµÀÖ÷ÃÜÂëµÄÇé¿öÏ»ָ´ Web Á¬½ÓµÄÃÜÂë¡£

CVE-2022-26307£ºLibreOfficeÖ÷ÃÜÔ¿±àÂë²»Íש¶´

LibreOffice Ö§³Ö½« Web Á¬½ÓµÄÃÜÂë´æ´¢ÔÚÓû§µÄÅäÖÃÊý¾Ý¿âÖÐ £¬´æ´¢µÄÃÜÂëʹÓÃÓû§ÌṩµÄµ¥¸öÖ÷ÃÜÔ¿½øÐмÓÃÜ¡£ÔÚÊÜÓ°ÏìµÄLibreOffic°æ±¾ÖÐ £¬ÓÉÓÚÖ÷ÃÜÔ¿±àÂë²»Í× £¬µ¼ÖÂÆäentropy´Ó128λ¼õÖÁ43λ £¬Äܹ»·ÃÎÊÓû§ÅäÖÃÊý¾ÝµÄ¶ñÒâÓû§¿ÉÄܻᱩÁ¦ÆÆ½â´æ´¢µÄÃÜÂë¡£

CVE-2022-26305£ºLibreOfficÖ¤ÊéÑé֤©¶´

LibreOffice Ö§³ÖºêµÄÖ´ÐÐ £¬Ä¬ÈÏÇé¿öÏ £¬½öµ±ºê´æ´¢ÔÚÊÜÐÅÈεÄÎļþλÖûòÓÉÊÜÐÅÈεÄÖ¤ÊéÇ©Ãûʱ £¬LibreOffice ²Å»áÖ´ÐкꡣΪ´Ë £¬LibreOffice »á½«Ö¤ÊéÓë´æ´¢ÔÚÓû§ÅäÖÃÊý¾Ý¿âÖеÄÊÜÐÅÈÎÖ¤ÊéÁÐ±í½øÐÐУÑé¡£µ«ÔÚÊÜÓ°ÏìµÄLibreOffic°æ±¾ÖÐ £¬ÓÉÓÚÖ¤ÊéÑéÖ¤²»ÕýÈ· £¬¿ÉÒÔͨ¹ýαÔìÖ¤ÊéÖ´ÐаüÂÞÔÚ²»ÊÜÐÅÈεĺêÖеÄÈÎÒâ´úÂë¡£´Ë©¶´ÒÑÔÚLibreOffice °æ±¾7.2.7¡¢7.3.2¼°¸ü¸ß°æ±¾ÖÐÐÞ¸´¡£

 

Ó°Ï췶Χ

LibreOffice °æ±¾< 7.2.7

LibreOffice °æ±¾< 7.3.3

 

0x02 ´¦Öý¨Òé

ĿǰÕâЩ©¶´ÒѾ­ÐÞ¸´ £¬ÊÜÓ°ÏìÓû§¿ÉÒÔÉý¼¶µ½LibreOffice °æ±¾7.2.7¡¢7.3.3»ò¸ü¸ß°æ±¾¡£

ÏÂÔØÁ´½Ó£º

https://www.libreoffice.org/download/download/

 

0x03 ²Î¿¼Á´½Ó

https://www.libreoffice.org/about-us/security/advisories/

https://www.libreoffice.org/about-us/security/advisories/cve-2022-26305/

https://www.libreoffice.org/about-us/security/advisories/cve-2022-26306/

 

0x04 ¸üа汾

°æ±¾

ÈÕÆÚ

ÐÞ¸ÄÄÚÈÝ

V1.0

2022-07-29

Ê×´ÎÐû²¼

 

0x05 ¸½Â¼

¶¶È¦Îª¶Ä¶øÉú¼ò½é

¶¶È¦Îª¶Ä¶øÉú½¨Á¢ÓÚ1996Äê £¬ÊÇÓÉÁôÃÀ²©Ê¿ÑÏÍû¼ÑŮʿ´´½¨µÄ¡¢ÓµÓÐÍêÈ«×ÔÖ÷֪ʶ²úȨµÄÐÅÏ¢Äþ¾²¸ß¿Æ¼¼ÆóÒµ¡£ÊǹúÄÚ×î¾ßʵÁ¦µÄÐÅÏ¢Äþ¾²²úÎï¡¢Äþ¾²·þÎñ½â¾ö·½°¸µÄÁ캽ÆóÒµÖ®Ò»¡£

¹«Ë¾×ܲ¿Î»ÓÚ±±¾©ÊÐÖйشåÈí¼þÔ°¶¶È¦Îª¶Ä¶øÉú´óÏà £¬¹«Ë¾Ô±¹¤½ü4000ÈË £¬Ñз¢ÍŶÓ1200ÓàÈË, ¼¼Êõ·þÎñÍŶÓ1300ÓàÈË¡£ÔÚÈ«¹ú¸÷Ê¡¡¢ÊС¢×ÔÖÎÇøÉèÁ¢·ÖÖ§»ú¹¹ÁùÊ®¶à¸ö £¬ÓµÓÐÁýÕÖÈ«¹úµÄÏúÊÛÌåϵ¡¢ÇþµÀÌåϵºÍ¼¼ÊõÖ§³ÖÌåϵ¡£¹«Ë¾ÓÚ2010Äê6ÔÂ23ÈÕÔÚÉîÛÚÖÐС°å¹ÒÅÆÉÏÊС££¨¹ÉƱ´úÂ룺002439£©

¶àÄêÀ´ £¬¶¶È¦Îª¶Ä¶øÉúÖÂÁ¦ÓÚÌṩ¾ßÓйú¼Ê¾ºÕùÁ¦µÄ×ÔÖ÷´´ÐµÄÄþ¾²²úÎïºÍ×î¼Ñʵ¼ù·þÎñ £¬×ÊÖú¿Í»§È«ÃæÌáÉýÆäIT»ù´¡ÉèÊ©µÄÄþ¾²ÐÔºÍÉú²úЧÄÜ £¬Îª´òÔìºÍÌáÉý¹ú¼Ê»¯µÄÃñ×åÐÅÏ¢Äþ¾²¹¤ÒµÁì¾üÆ·ÅÆ¶ø²»Ð¸Å¬Á¦¡£

 

¹ØÓÚ¶¶È¦Îª¶Ä¶øÉú

¶¶È¦Îª¶Ä¶øÉúÄþ¾²Ó¦¼±ÏìÓ¦ÖÐÐÄÖ÷ÒªÕë¶ÔÖØÒªÄþ¾²Â©¶´µÄÔ¤¾¯¡¢¸ú×ٺͷÖÏíÈ«Çò×îеÄÍþвÇ鱨ºÍÄþ¾²³ÂËß¡£

¹Ø×¢ÒÔϹ«ÖںŠ£¬»ñȡȫÇò×îÐÂÄþ¾²×ÊѶ£º

image.png