Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Message-ID: <YAlV7n+yLVBceb3c@f195.suse.de>
Date: Thu, 21 Jan 2021 11:22:38 +0100
From: Matthias Gerstner <mgerstner@...e.de>
To: oss-security@...ts.openwall.com
Subject: Re: libreoffice-online "loolforkit" privileged
 program local root exploit

On Mon, Jan 18, 2021 at 04:07:40PM +0100, Matthias Gerstner wrote:
> Formally libreoffice-online is covered by the "Document Foundation" CNA,
> therefore I did not request a CVE for this via the Mitre CVE form. I
> will try to contact the CNA directly in this matter.

The Document Foundation assigned CVE-2021-25630 for the missing
enforcement of only allowing the "loolforkit" user to access the
sensitive features of the program.

Cheers

Matthias

Download attachment "signature.asc" of type "application/pgp-signature" (834 bytes)

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.