PT-2018-2471 · Document Foundation+5 · Libreoffice+5

Andrew Krasichkov

+2

·

Publicado

2018-02-09

·

Atualizado

2019-10-03

·

CVE-2018-6871

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions LibreOffice versions prior to 5.4.5 LibreOffice versions 6.x prior to 6.0.1
Description The issue is related to the COM.MICROSOFT.WEBSERVICE function in LibreOffice, which allows remote attackers to read arbitrary files via =WEBSERVICE calls in a document. This is due to inadequate management of registration data. An attacker can exploit this issue by sending a specially crafted request to gain access to protected information.
Recommendations For versions prior to 5.4.5, update to version 5.4.5 or later. For versions 6.x prior to 6.0.1, update to version 6.0.1 or later. As a temporary workaround, consider disabling the COM.MICROSOFT.WEBSERVICE function until a patch is available.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2018-1273
BDU:2019-00714
CESA-2018_0418
CESA-2018_0517
CVE-2018-6871
DSA-4111-1
DSA-4111-2
MGASA-2018-0271
OPENSUSE-SU-2018_0446-1
RHSA-2018:0418
RHSA-2018:0517
RHSA-2018_0418
RHSA-2018_0517
SUSE-SU-2018:0428-1
SUSE-SU-2018:0443-1
SUSE-SU-2018:1076-1
SUSE-SU-2018_0428-1
SUSE-SU-2018_0443-1
USN-3579-1

Produtos afetados

Alt Linux
Centos
Libreoffice
Red Hat
Suse
Ubuntu