Unrated severityNVD Advisory· Published Apr 15, 2018· Updated Aug 5, 2024
CVE-2018-10119
CVE-2018-10119
Description
sot/source/sdstor/stgstrms.cxx in LibreOffice before 5.4.5.1 and 6.x before 6.0.1.1 uses an incorrect integer data type in the StgSmallStrm class, which allows remote attackers to cause a denial of service (use-after-free with write access) or possibly have unspecified other impact via a crafted document that uses the structured storage ole2 wrapper file format.
Affected products
4- osv-coords4 versionspkg:rpm/opensuse/libreoffice&distro=openSUSE%20Tumbleweedpkg:rpm/suse/libreoffice&distro=SUSE%20Linux%20Enterprise%20Desktop%2012%20SP3pkg:rpm/suse/libreoffice&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP3pkg:rpm/suse/libreoffice&distro=SUSE%20Linux%20Enterprise%20Workstation%20Extension%2012%20SP3
< 7.1.5.2-3.13+ 3 more
- (no CPE)range: < 7.1.5.2-3.13
- (no CPE)range: < 6.0.4.2-43.33.1
- (no CPE)range: < 6.0.4.2-43.33.1
- (no CPE)range: < 6.0.4.2-43.33.1
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
11- access.redhat.com/errata/RHSA-2018:3054mitrevendor-advisoryx_refsource_REDHAT
- usn.ubuntu.com/3883-1/mitrevendor-advisoryx_refsource_UBUNTU
- www.debian.org/security/2018/dsa-4178mitrevendor-advisoryx_refsource_DEBIAN
- bugs.chromium.org/p/oss-fuzz/issues/detailmitrex_refsource_MISC
- gerrit.libreoffice.orgmitrex_refsource_MISC
- gerrit.libreoffice.orgmitrex_refsource_MISC
- gerrit.libreoffice.orgmitrex_refsource_MISC
- gerrit.libreoffice.orgmitrex_refsource_MISC
- gerrit.libreoffice.org/gitwebmitrex_refsource_MISC
- lists.debian.org/debian-lts-announce/2018/04/msg00021.htmlmitremailing-listx_refsource_MLIST
- www.libreoffice.org/about-us/security/advisories/cve-2018-10119/mitrex_refsource_MISC
News mentions
0No linked articles in our index yet.