﻿{"id":496,"date":"2019-02-06T13:43:28","date_gmt":"2019-02-06T19:43:28","guid":{"rendered":"https:\/\/www.uv.mx\/csirt\/?p=496"},"modified":"2019-02-06T13:43:28","modified_gmt":"2019-02-06T19:43:28","slug":"06-02-2019-vulnerabilidad-en-openoffice-y-libreoffice","status":"publish","type":"post","link":"https:\/\/www.uv.mx\/csirt\/boletines\/vulnerabilidades\/06-02-2019-vulnerabilidad-en-openoffice-y-libreoffice\/","title":{"rendered":"06\/02\/2019 Vulnerabilidad en OpenOffice y LibreOffice"},"content":{"rendered":"<p>&nbsp;<\/p>\n<div style=\"width: 752px;max-width: 752px;height: auto;border: 1px solid #369;margin: 0px auto;background-color: #fff\">\n<p><img decoding=\"async\" style=\"width: 750px\" src=\"http:\/\/boletines.uv.mx\/images\/images\/boletin-encabezado.jpg\" alt=\"\" \/><\/p>\n<table style=\"width: 100%\" border=\"0\" cellspacing=\"1\" cellpadding=\"1\" align=\"center\">\n<tbody>\n<tr>\n<td><img decoding=\"async\" style=\"width: 190px;height: 25px\" src=\"http:\/\/boletines.uv.mx\/images\/images\/cintillo_importante.jpg\" alt=\"\" \/><\/td>\n<td style=\"text-align: right\"><span style=\"font-size: 18px\"><span style=\"color: #666666\"><span style=\"font-family: tahoma,geneva,sans-serif\">06 de febrero de 2019<\/span><\/span><\/span><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<hr \/>\n<div style=\"background-color: #e6e6e6;line-height: 1.4\"><strong>Vulnerabilidad en OpenOffice y LibreOffice<\/strong><\/div>\n<div style=\"background-color: #e6e6e6;line-height: 1.4\"><span style=\"font-size: 16px\">ID: 06021901<\/span><\/div>\n<div style=\"background-color: #ffffff;line-height: 1.4\">\n<hr \/>\n<\/div>\n<div style=\"background-color: #f5f5f5;line-height: 1.4\">\n<p><span style=\"color: #28519b\"><span style=\"font-size: 16px\"><strong>Descripci\u00f3n<\/strong><\/span><\/span><\/p>\n<p style=\"text-align: justify\">El investigador de seguridad Alex Inf\u00fchr ha descubierto una vulnerabilidad de ejecuci\u00f3n de c\u00f3digo remoto (RCE) en estas dos suites de oficina de c\u00f3digo abierto, que podr\u00eda activarse con s\u00f3lo abrir un archivo ODT (Open Document Text) maliciosamente creado aprovechandose de una falla con el identificador CVE-2018-16858 para ejecutar autom\u00e1ticamente una librer\u00eda espec\u00edfica de Phyton llamado <em>\u00abpydoc.py\u00bb<\/em> que viene incluido con el propio interprete de Phyton.<\/p>\n<\/div>\n<div style=\"background-color: #ffffff;line-height: 1.4\">\n<p>&nbsp;<\/p>\n<p><span style=\"color: #28519b\"><strong><span style=\"font-size: 16px\">Productos afectados<\/span><\/strong><\/span><\/p>\n<\/div>\n<div style=\"background-color: #f7931e;line-height: 1.4\">\n<p>&nbsp;<\/p>\n<\/div>\n<div style=\"background-color: #ffffff;line-height: 1.4\">\n<p>Usuarios de Windows, Linux o macOS que tengan instalado esta suite ofim\u00e1tica<\/p>\n<ul>\n<li>OpenOffice 4.1.6<\/li>\n<li>LibreOffice con versi\u00f3n anterior a 6.0.7 o 6.1.3<\/li>\n<\/ul>\n<hr size=\"2\" \/>\n<\/div>\n<div style=\"background-color: #f5f5f5;line-height: 1.4\">\n<p><span style=\"color: #28519b\"><span style=\"font-size: 16px\"><strong>Soluci\u00f3n:<\/strong><\/span><\/span><\/p>\n<p style=\"text-align: justify\">Actualizar a la \u00faltima versi\u00f3n de LibreOffice 6.1.4 que se encuentra disponible para su descarga e instalaci\u00f3n en: <a href=\"http:\/\/boletines.uv.mx\/\/lt.php?tid=fB1RXAUHVFUBUE8CXVFWSwYBBQIbAg8CAUwHUVcHBVNWVlYOAQRLUgMGAQcMUgFLBgIHWxtXAVJXTF0NAABMAwZQBQAGAgIGA1tTGAlVW1FXVgQGG1BZUlVMUAcAU0wHBVVXFQQGAgVRAQAHXVBSUA\">libreoffice.org <\/a><\/p>\n<p style=\"text-align: justify\">De manera provisional hasta que se publique una actualizaci\u00f3n de seguridad, los usuarios de OpenOffice pueden eliminar o renombrar el archivo <em>pythonscript.py<\/em> en la carpeta de instalaci\u00f3n (<em>\\OpenOffice 4\\program<\/em>) para desactivar la compatibilidad con Phyton.<\/p>\n<p>Para m\u00e1s informaci\u00f3n:<\/p>\n<p><a href=\"https:\/\/insert-script.blogspot.com\/2019\/02\/libreoffice-cve-2018-16858-remote-code.html\">https:\/\/insert-script.blogspot.com\/2019\/02\/libreoffice-cve-2018-16858-remote-code.html<\/a><\/p>\n<\/div>\n<div style=\"background-color: #ffffff;line-height: 1.4\">\n<hr \/>\n<\/div>\n<p>&nbsp;<\/p>\n<p><img decoding=\"async\" style=\"width: 750px;height: 120px\" src=\"http:\/\/boletines.uv.mx\/images\/images\/cintillo_inferior.jpg\" alt=\"\" \/><\/p>\n<\/div>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>&nbsp; 06 de febrero de 2019 Vulnerabilidad en OpenOffice y LibreOffice ID: 06021901 Descripci\u00f3n El investigador de seguridad Alex Inf\u00fchr ha descubierto una vulnerabilidad de ejecuci\u00f3n de c\u00f3digo remoto (RCE) en estas dos suites de oficina de c\u00f3digo abierto, que podr\u00eda activarse con s\u00f3lo abrir un archivo ODT (Open Document Text) maliciosamente creado aprovechandose de [&hellip;]<\/p>\n","protected":false},"author":2037,"featured_media":465,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"ventana_nueva":"","tipo_url":"","url":"","extracto":"","imagen_halign":"","imagen_valign":"","bg_size":"","text_hide":"","media_url":"","tipo_media":"","video_url":"","video_pos":"","video_youtube":"","footnotes":""},"categories":[16,15],"tags":[],"class_list":["post-496","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-importantes","category-vulnerabilidades"],"_links":{"self":[{"href":"https:\/\/www.uv.mx\/csirt\/wp-json\/wp\/v2\/posts\/496","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.uv.mx\/csirt\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.uv.mx\/csirt\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.uv.mx\/csirt\/wp-json\/wp\/v2\/users\/2037"}],"replies":[{"embeddable":true,"href":"https:\/\/www.uv.mx\/csirt\/wp-json\/wp\/v2\/comments?post=496"}],"version-history":[{"count":0,"href":"https:\/\/www.uv.mx\/csirt\/wp-json\/wp\/v2\/posts\/496\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.uv.mx\/csirt\/wp-json\/wp\/v2\/media\/465"}],"wp:attachment":[{"href":"https:\/\/www.uv.mx\/csirt\/wp-json\/wp\/v2\/media?parent=496"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.uv.mx\/csirt\/wp-json\/wp\/v2\/categories?post=496"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.uv.mx\/csirt\/wp-json\/wp\/v2\/tags?post=496"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}