CVE-2023-0950


Array Index UnderFlow in Calc Formula Parsing

Improper Validation of Array Index vulnerability in the spreadsheet component of The Document Foundation LibreOffice allows an attacker to craft a spreadsheet document that will cause an array index underflow when loaded. In the affected versions of LibreOffice certain malformed spreadsheet formulas, such as AGGREGATE, could be created with less parameters passed to the formula interpreter than it expected, leading to an array index underflow, in which case there is a risk that arbitrary code could be executed. This issue affects: The Document Foundation LibreOffice 7.4 versions prior to 7.4.6; 7.5 versions prior to 7.5.1.



We have discovered 97 live websites that are affected by CVE-2023-0950.

Contact us to get more info




Affected Software

Product  LibreOffice
Category Content Management System
Vulnerable Versions
  • from 7.4 before 7.4.6
  • from 7.5 before 7.5.1
Total Vulnerable Versions195
Vulnerable Domains97 live websites (2.88% of LibreOffice install base)


Common Weakness Enumeration


CWE-129 Improper Validation of Array Index



Details

  • Published - May 25, 2023
  • Updated - Nov 26, 2023

Credits

  • Secusmart GmbH for discovering and reporting the issue
  • Eike Rathke of Red Hat, Inc. for a solution





Countries

United States18 websites



Germany18 websites
Italy11 websites
Russia7 websites
France6 websites
GB4 websites
Netherlands4 websites
Belgium3 websites
Australia2 websites
Brazil2 websites

TLDs

.com22 websites
.de15 websites
.net10 websites
.fr6 websites
.org5 websites
.ru5 websites
.nl4 websites
.it4 websites
.be3 websites
.com.br2 websites

Vulnerable Versions

Vulnerable versions are highlighted in red


References


Websites affected by CVE-2023-0950

Top websites that are affected by CVE-2023-0950. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*****************.*****.ru Russia*,***,***
************************.net Italy*,***,***
***.************************.net Italy*,***,***
*************.com Switzerland*,***,***
**************.fr France*,***,***
*****************.com United States*,***,***
***********.de Germany*,***,***
*******.de Germany*,***,***
***.**********.**.uk GB*,***,***
*******************.***.in India*,***,***
See full domain list