PT-2018-2471 · Document Foundation+5 · Libreoffice+5

Andrew Krasichkov

+2

·

Published

2018-02-09

·

Updated

2019-10-03

·

CVE-2018-6871

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions LibreOffice versions prior to 5.4.5 LibreOffice versions 6.x prior to 6.0.1
Description The issue is related to the COM.MICROSOFT.WEBSERVICE function in LibreOffice, which allows remote attackers to read arbitrary files via =WEBSERVICE calls in a document. This is due to inadequate management of registration data. An attacker can exploit this issue by sending a specially crafted request to gain access to protected information.
Recommendations For versions prior to 5.4.5, update to version 5.4.5 or later. For versions 6.x prior to 6.0.1, update to version 6.0.1 or later. As a temporary workaround, consider disabling the COM.MICROSOFT.WEBSERVICE function until a patch is available.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2018-1273
BDU:2019-00714
CESA-2018_0418
CESA-2018_0517
CVE-2018-6871
DSA-4111-1
DSA-4111-2
MGASA-2018-0271
OPENSUSE-SU-2018_0446-1
RHSA-2018:0418
RHSA-2018:0517
RHSA-2018_0418
RHSA-2018_0517
SUSE-SU-2018:0428-1
SUSE-SU-2018:0443-1
SUSE-SU-2018:1076-1
SUSE-SU-2018_0428-1
SUSE-SU-2018_0443-1
USN-3579-1

Affected Products

Alt Linux
Centos
Libreoffice
Red Hat
Suse
Ubuntu