Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-16858

Опубликовано: 01 фев. 2019
Источник: redhat
CVSS3: 7.8
EPSS Средний

Описание

It was found that libreoffice before versions 6.0.7 and 6.1.3 was vulnerable to a directory traversal attack which could be used to execute arbitrary macros bundled with a document. An attacker could craft a document, which when opened by LibreOffice, would execute a Python method from a script in any arbitrary file system location, specified relative to the LibreOffice install location.

It was found that libreoffice was vulnerable to a directory traversal attack which could be used to execute arbitrary macros bundled with a document. An attacker could craft a document, which when opened by LibreOffice, would execute a Python method from a script in any arbitrary file system location, specified relative to the LibreOffice install location.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6libreofficeOut of support scope
Red Hat Enterprise Linux 8libreofficeNot affected
Red Hat Enterprise Linux 7libreofficeFixedRHSA-2019:213008.08.2019

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-356
https://bugzilla.redhat.com/show_bug.cgi?id=1649841libreoffice: Arbitrary python functions in arbitrary modules on the filesystem can be executed without warning

EPSS

Процентиль: 99%
0.67321
Средний

7.8 High

CVSS3

Связанные уязвимости

CVSS3: 7.8
ubuntu
больше 7 лет назад

It was found that libreoffice before versions 6.0.7 and 6.1.3 was vulnerable to a directory traversal attack which could be used to execute arbitrary macros bundled with a document. An attacker could craft a document, which when opened by LibreOffice, would execute a Python method from a script in any arbitrary file system location, specified relative to the LibreOffice install location.

CVSS3: 7.8
nvd
больше 7 лет назад

It was found that libreoffice before versions 6.0.7 and 6.1.3 was vulnerable to a directory traversal attack which could be used to execute arbitrary macros bundled with a document. An attacker could craft a document, which when opened by LibreOffice, would execute a Python method from a script in any arbitrary file system location, specified relative to the LibreOffice install location.

CVSS3: 7.8
debian
больше 7 лет назад

It was found that libreoffice before versions 6.0.7 and 6.1.3 was vuln ...

suse-cvrf
почти 7 лет назад

Security update for LibreOffice

suse-cvrf
около 7 лет назад

Security update for libreoffice

EPSS

Процентиль: 99%
0.67321
Средний

7.8 High

CVSS3