Web Hack List

Collected research

A Tale of Exploitation in Spreadsheet File Conversions

Server-side document conversion with LibreOffice is fingerprinted through spreadsheet INFO functions and PDF metadata, then abused because LibreOffice picks the format from file contents, not the extension. An ODS or EPS file renamed to .xlsx reaches OLE xlinks, ODF text sections or Ghostscript, giving local file read and SSRF to cloud metadata; unoconv silently updating links is CVE-2019-17400.

Record

Researcher
Brett Buerhaus, Cody Brocious, Sam Erb and Olivier Beg
Published by
buer.haus
Topic
Other

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Brett Buerhaus, Cody Brocious, Sam Erb and Olivier Beg, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .