Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-10583

Опубликовано: 01 мая 2018
Источник: redhat
CVSS3: 4.3
EPSS Высокий

Описание

An information disclosure vulnerability occurs when LibreOffice 6.0.3 and Apache OpenOffice Writer 4.1.5 automatically process and initiate an SMB connection embedded in a malicious file, as demonstrated by xlink:href=file://192.168.0.2/test.jpg within an office:document-content element in a .odt XML document.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6libreofficeWill not fix
Red Hat Enterprise Linux 8libreofficeNot affected
Red Hat Enterprise Linux 7libreofficeFixedRHSA-2018:305430.10.2018

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-200
https://bugzilla.redhat.com/show_bug.cgi?id=1574998libreoffice: Information disclosure via SMB connection embedded in malicious file

EPSS

Процентиль: 99%
0.71895
Высокий

4.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 8 лет назад

An information disclosure vulnerability occurs when LibreOffice 6.0.3 and Apache OpenOffice Writer 4.1.5 automatically process and initiate an SMB connection embedded in a malicious file, as demonstrated by xlink:href=file://192.168.0.2/test.jpg within an office:document-content element in a .odt XML document.

CVSS3: 7.5
nvd
почти 8 лет назад

An information disclosure vulnerability occurs when LibreOffice 6.0.3 and Apache OpenOffice Writer 4.1.5 automatically process and initiate an SMB connection embedded in a malicious file, as demonstrated by xlink:href=file://192.168.0.2/test.jpg within an office:document-content element in a .odt XML document.

CVSS3: 7.5
debian
почти 8 лет назад

An information disclosure vulnerability occurs when LibreOffice 6.0.3 ...

suse-cvrf
около 7 лет назад

Security update for LibreOffice and dependency libraries

suse-cvrf
больше 7 лет назад

Security update for libreoffice

EPSS

Процентиль: 99%
0.71895
Высокий

4.3 Medium

CVSS3