¡¾Îó²îͨ¸æ¡¿LibreOffice 7Ô¶à¸öÇå¾²Îó²î
Ðû²¼Ê±¼ä 2022-07-290x00 Îó²î¸ÅÊö
2022Äê7ÔÂ25ÈÕ£¬£¬£¬£¬£¬£¬£¬LibreOfficeÐû²¼Ç徲ͨ¸æ£¬£¬£¬£¬£¬£¬£¬ÐÞ¸´ÁËLibreOfficeÈí¼þÖеĶà¸öÇå¾²Îó²î£¬£¬£¬£¬£¬£¬£¬ÕâЩÎó²î¿ÉÄܵ¼ÖÂÐÅϢй¶»ò´úÂëÖ´ÐС£¡£¡£¡£¡£¡£¡£¡£
0x01 Îó²îÏêÇé
LibreOfficeÊÇÒ»¿îÃâ·ÑÇÒ¹¦Ð§Ç¿Ê¢µÄ°ì¹«Ì×¼þ£¬£¬£¬£¬£¬£¬£¬ËüÊÇOpenOffice.org°ì¹«Ì×¼þÑÜÉú°æ¡£¡£¡£¡£¡£¡£¡£¡£
LibreOffice½üÆÚÐÞ¸´µÄ3¸öÎó²îÈçÏ£º
CVE-2022-26306£ºLibreOffice¼ÓÃÜÇå¾²Îó²î
LibreOffice Ö§³Ö½« Web ÅþÁ¬µÄÃÜÂë´æ´¢ÔÚÓû§µÄÉèÖÃÊý¾Ý¿âÖУ¬£¬£¬£¬£¬£¬£¬´æ´¢µÄÃÜÂëʹÓÃÓû§ÌṩµÄµ¥¸öÖ÷ÃÜÔ¿¾ÙÐмÓÃÜ¡£¡£¡£¡£¡£¡£¡£¡£ÔÚÊÜÓ°ÏìµÄLibreOffic°æ±¾ÖУ¬£¬£¬£¬£¬£¬£¬ÓÉÓÚ¼ÓÃÜËùÐèµÄ³õʼ»¯ÏòÁ¿Ê¼ÖÕÏàͬ£¬£¬£¬£¬£¬£¬£¬µ¼ÖÈÎÃüÜÇå¾²ÐÔ±»Ï÷Èõ£¬£¬£¬£¬£¬£¬£¬Äܹ»»á¼ûÓû§ÉèÖÃÊý¾ÝµÄ¶ñÒâÓû§¿ÉÒÔÔÚ²»ÖªµÀÖ÷ÃÜÂëµÄÇéÐÎÏ»ָ´ Web ÅþÁ¬µÄÃÜÂë¡£¡£¡£¡£¡£¡£¡£¡£
CVE-2022-26307£ºLibreOfficeÖ÷ÃÜÔ¿±àÂë²»µ±Îó²î
LibreOffice Ö§³Ö½« Web ÅþÁ¬µÄÃÜÂë´æ´¢ÔÚÓû§µÄÉèÖÃÊý¾Ý¿âÖУ¬£¬£¬£¬£¬£¬£¬´æ´¢µÄÃÜÂëʹÓÃÓû§ÌṩµÄµ¥¸öÖ÷ÃÜÔ¿¾ÙÐмÓÃÜ¡£¡£¡£¡£¡£¡£¡£¡£ÔÚÊÜÓ°ÏìµÄLibreOffic°æ±¾ÖУ¬£¬£¬£¬£¬£¬£¬ÓÉÓÚÖ÷ÃÜÔ¿±àÂë²»µ±£¬£¬£¬£¬£¬£¬£¬µ¼ÖÂÆäentropy´Ó128λ¼õÖÁ43룬£¬£¬£¬£¬£¬£¬Äܹ»»á¼ûÓû§ÉèÖÃÊý¾ÝµÄ¶ñÒâÓû§¿ÉÄܻᱩÁ¦ÆÆ½â´æ´¢µÄÃÜÂë¡£¡£¡£¡£¡£¡£¡£¡£
CVE-2022-26305£ºLibreOfficÖ¤ÊéÑéÖ¤Îó²î
LibreOffice Ö§³ÖºêµÄÖ´ÐУ¬£¬£¬£¬£¬£¬£¬Ä¬ÈÏÇéÐÎÏ£¬£¬£¬£¬£¬£¬£¬½öµ±ºê´æ´¢ÔÚÊÜÐÅÈεÄÎļþλÖûòÓÉÊÜÐÅÈεÄÖ¤ÊéÊðÃûʱ£¬£¬£¬£¬£¬£¬£¬LibreOffice ²Å»áÖ´Ðкꡣ¡£¡£¡£¡£¡£¡£¡£Îª´Ë£¬£¬£¬£¬£¬£¬£¬LibreOffice »á½«Ö¤ÊéÓë´æ´¢ÔÚÓû§ÉèÖÃÊý¾Ý¿âÖеÄÊÜÐÅÈÎÖ¤ÊéÁбí¾ÙÐÐУÑé¡£¡£¡£¡£¡£¡£¡£¡£µ«ÔÚÊÜÓ°ÏìµÄLibreOffic°æ±¾ÖУ¬£¬£¬£¬£¬£¬£¬ÓÉÓÚÖ¤ÊéÑéÖ¤²»×¼È·£¬£¬£¬£¬£¬£¬£¬¿ÉÒÔͨ¹ýαÔìÖ¤ÊéÖ´ÐаüÀ¨ÔÚ²»ÊÜÐÅÈεĺêÖеÄí§Òâ´úÂë¡£¡£¡£¡£¡£¡£¡£¡£´ËÎó²îÒÑÔÚLibreOffice °æ±¾7.2.7¡¢7.3.2¼°¸ü¸ß°æ±¾ÖÐÐÞ¸´¡£¡£¡£¡£¡£¡£¡£¡£
Ó°Ïì¹æÄ£
LibreOffice °æ±¾< 7.2.7
LibreOffice °æ±¾< 7.3.3
0x02 ´¦Öóͷ£½¨Òé
ÏÖÔÚÕâЩÎó²îÒѾÐÞ¸´£¬£¬£¬£¬£¬£¬£¬ÊÜÓ°ÏìÓû§¿ÉÒÔÉý¼¶µ½LibreOffice °æ±¾7.2.7¡¢7.3.3»ò¸ü¸ß°æ±¾¡£¡£¡£¡£¡£¡£¡£¡£
ÏÂÔØÁ´½Ó£º
https://www.libreoffice.org/download/download/
0x03 ²Î¿¼Á´½Ó
https://www.libreoffice.org/about-us/security/advisories/
https://www.libreoffice.org/about-us/security/advisories/cve-2022-26305/
https://www.libreoffice.org/about-us/security/advisories/cve-2022-26306/
0x04 ¸üа汾
°æ±¾ | ÈÕÆÚ | ÐÞ¸ÄÄÚÈÝ |
V1.0 | 2022-07-29 | Ê×´ÎÐû²¼ |
0x05 ¸½Â¼
¿·¢k8¼ò½é
¿·¢k8½¨ÉèÓÚ1996Ä꣬£¬£¬£¬£¬£¬£¬ÊÇÓÉÁôÃÀ²©Ê¿ÑÏÍû¼ÑŮʿ½¨ÉèµÄ¡¢ÓµÓÐÍêÈ«×ÔÖ÷֪ʶ²úȨµÄÐÅÏ¢Çå¾²¸ß¿Æ¼¼ÆóÒµ¡£¡£¡£¡£¡£¡£¡£¡£ÊǺ£ÄÚ×î¾ßʵÁ¦µÄÐÅÏ¢Çå¾²²úÆ·¡¢Ç徲ЧÀͽâ¾ö¼Æ»®µÄÁ캽ÆóÒµÖ®Ò»¡£¡£¡£¡£¡£¡£¡£¡£
¹«Ë¾×ܲ¿Î»ÓÚ±±¾©ÊÐÖйشåÈí¼þÔ°¿·¢k8´óÏ㬣¬£¬£¬£¬£¬£¬¹«Ë¾Ô±¹¤½ü4000ÈË£¬£¬£¬£¬£¬£¬£¬Ñз¢ÍŶÓ1200ÓàÈË, ÊÖÒÕЧÀÍÍŶÓ1300ÓàÈË¡£¡£¡£¡£¡£¡£¡£¡£ÔÚÌìϸ÷Ê¡¡¢ÊС¢×ÔÖÎÇøÉèÁ¢·ÖÖ§»ú¹¹ÁùÊ®¶à¸ö£¬£¬£¬£¬£¬£¬£¬ÓµÓÐÁýÕÖÌìϵÄÏúÊÛϵͳ¡¢ÇþµÀϵͳºÍÊÖÒÕÖ§³Öϵͳ¡£¡£¡£¡£¡£¡£¡£¡£¹«Ë¾ÓÚ2010Äê6ÔÂ23ÈÕÔÚÉîÛÚÖÐС°å¹ÒÅÆÉÏÊС£¡£¡£¡£¡£¡£¡£¡££¨¹ÉƱ´úÂ룺002439£©
¶àÄêÀ´£¬£¬£¬£¬£¬£¬£¬¿·¢k8ÖÂÁ¦ÓÚÌṩ¾ßÓйú¼Ê¾ºÕùÁ¦µÄ×ÔÖ÷Á¢ÒìµÄÇå¾²²úÆ·ºÍ×î¼Ñʵ¼ùЧÀÍ£¬£¬£¬£¬£¬£¬£¬×ÊÖú¿Í»§ÖÜÈ«ÌáÉýÆäIT»ù´¡ÉèÊ©µÄÇå¾²ÐÔºÍÉú²úЧÄÜ£¬£¬£¬£¬£¬£¬£¬Îª´òÔìºÍÌáÉý¹ú¼Ê»¯µÄÃñ×åÐÅÏ¢Çå¾²¹¤ÒµÁì¾üÆ·ÅÆ¶ø²»Ð¸Æð¾¢¡£¡£¡£¡£¡£¡£¡£¡£
¹ØÓÚ¿·¢k8
¿·¢k8Çå¾²Ó¦¼±ÏìÓ¦ÖÐÐÄÖ÷ÒªÕë¶ÔÖ÷ÒªÇå¾²Îó²îµÄÔ¤¾¯¡¢¸ú×ٺͷÖÏíÈ«Çò×îеÄÍþвÇ鱨ºÍÇå¾²±¨¸æ¡£¡£¡£¡£¡£¡£¡£¡£
¹Ø×¢ÒÔϹ«Öںţ¬£¬£¬£¬£¬£¬£¬»ñȡȫÇò×îÐÂÇå¾²×ÊѶ£º



¾©¹«Íø°²±¸11010802024551ºÅ