Unrated severityNVD Advisory· Published May 1, 2018· Updated Aug 5, 2024
CVE-2018-10583
CVE-2018-10583
Description
An information disclosure vulnerability occurs when LibreOffice 6.0.3 and Apache OpenOffice Writer 4.1.5 automatically process and initiate an SMB connection embedded in a malicious file, as demonstrated by xlink:href=file://192.168.0.2/test.jpg within an office:document-content element in a .odt XML document.
Affected products
18- osv-coords18 versionspkg:rpm/opensuse/libreoffice&distro=openSUSE%20Tumbleweedpkg:rpm/suse/libepubgen&distro=SUSE%20Linux%20Enterprise%20Workstation%20Extension%2015pkg:rpm/suse/liblangtag&distro=SUSE%20Linux%20Enterprise%20Workstation%20Extension%2015pkg:rpm/suse/libmwaw&distro=SUSE%20Linux%20Enterprise%20Workstation%20Extension%2015pkg:rpm/suse/libnumbertext&distro=SUSE%20Linux%20Enterprise%20Workstation%20Extension%2015pkg:rpm/suse/libreoffice&distro=SUSE%20Linux%20Enterprise%20Desktop%2012%20SP3pkg:rpm/suse/libreoffice&distro=SUSE%20Linux%20Enterprise%20Desktop%2012%20SP4pkg:rpm/suse/libreoffice&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP3pkg:rpm/suse/libreoffice&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP4pkg:rpm/suse/libreoffice&distro=SUSE%20Linux%20Enterprise%20Workstation%20Extension%2012%20SP3pkg:rpm/suse/libreoffice&distro=SUSE%20Linux%20Enterprise%20Workstation%20Extension%2012%20SP4pkg:rpm/suse/libreoffice&distro=SUSE%20Linux%20Enterprise%20Workstation%20Extension%2015pkg:rpm/suse/libstaroffice&distro=SUSE%20Linux%20Enterprise%20Workstation%20Extension%2015pkg:rpm/suse/libwps&distro=SUSE%20Linux%20Enterprise%20Workstation%20Extension%2015pkg:rpm/suse/myspell-dictionaries&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015pkg:rpm/suse/myspell-dictionaries&distro=SUSE%20Linux%20Enterprise%20Workstation%20Extension%2015pkg:rpm/suse/xmlsec1&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Package%20Hub%2015pkg:rpm/suse/xmlsec1&distro=SUSE%20Linux%20Enterprise%20Workstation%20Extension%2015
< 7.1.5.2-3.13+ 17 more
- (no CPE)range: < 7.1.5.2-3.13
- (no CPE)range: < 0.1.1-3.3.1
- (no CPE)range: < 0.6.2-3.3.1
- (no CPE)range: < 0.3.14-4.3.1
- (no CPE)range: < 1.0.5-1.3.1
- (no CPE)range: < 6.0.5.2-43.38.5
- (no CPE)range: < 6.0.5.2-43.38.5
- (no CPE)range: < 6.0.5.2-43.38.5
- (no CPE)range: < 6.0.5.2-43.38.5
- (no CPE)range: < 6.0.5.2-43.38.5
- (no CPE)range: < 6.0.5.2-43.38.5
- (no CPE)range: < 6.0.5.2-3.3.5
- (no CPE)range: < 0.0.6-3.3.1
- (no CPE)range: < 0.4.9-3.3.1
- (no CPE)range: < 20181025-3.6.1
- (no CPE)range: < 20181025-3.6.1
- (no CPE)range: < 1.2.26-3.3.1
- (no CPE)range: < 1.2.26-3.3.1
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
9- www.exploit-db.com/exploits/44564/mitreexploitx_refsource_EXPLOIT-DB
- access.redhat.com/errata/RHSA-2018:3054mitrevendor-advisoryx_refsource_REDHAT
- usn.ubuntu.com/3883-1/mitrevendor-advisoryx_refsource_UBUNTU
- seclists.org/fulldisclosure/2020/Oct/26mitremailing-listx_refsource_FULLDISC
- secureyourit.co.uk/wp/2018/05/01/creating-malicious-odt-files/mitrex_refsource_MISC
- lists.apache.org/thread.html/0598708912978b27121b2e380b44a225c706aca882cd1da6a955a0af%40%3Cdev.openoffice.apache.org%3Emitremailing-listx_refsource_MLIST
- lists.apache.org/thread.html/6c65f22306c36c95e75f8d2b7f49cfcbeb0a4614245c20934612a39d%40%3Cdev.openoffice.apache.org%3Emitremailing-listx_refsource_MLIST
- lists.apache.org/thread.html/c8fd59ac77b42aac90eb5c59b87f3ab59b5e0c3bfb4819aa649a2909%40%3Cdev.openoffice.apache.org%3Emitremailing-listx_refsource_MLIST
- security-tracker.debian.org/tracker/CVE-2018-10583mitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.