Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-16858

Опубликовано: 01 фев. 2019
Источник: redhat
CVSS3: 7.8
EPSS Критический

Описание

It was found that libreoffice before versions 6.0.7 and 6.1.3 was vulnerable to a directory traversal attack which could be used to execute arbitrary macros bundled with a document. An attacker could craft a document, which when opened by LibreOffice, would execute a Python method from a script in any arbitrary file system location, specified relative to the LibreOffice install location.

It was found that libreoffice was vulnerable to a directory traversal attack which could be used to execute arbitrary macros bundled with a document. An attacker could craft a document, which when opened by LibreOffice, would execute a Python method from a script in any arbitrary file system location, specified relative to the LibreOffice install location.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6libreofficeOut of support scope
Red Hat Enterprise Linux 8libreofficeNot affected
Red Hat Enterprise Linux 7libreofficeFixedRHSA-2019:213008.08.2019

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-356
https://bugzilla.redhat.com/show_bug.cgi?id=1649841libreoffice: Arbitrary python functions in arbitrary modules on the filesystem can be executed without warning

EPSS

Процентиль: 100%
0.92343
Критический

7.8 High

CVSS3

Связанные уязвимости

CVSS3: 7.8
ubuntu
почти 7 лет назад

It was found that libreoffice before versions 6.0.7 and 6.1.3 was vulnerable to a directory traversal attack which could be used to execute arbitrary macros bundled with a document. An attacker could craft a document, which when opened by LibreOffice, would execute a Python method from a script in any arbitrary file system location, specified relative to the LibreOffice install location.

CVSS3: 7.8
nvd
почти 7 лет назад

It was found that libreoffice before versions 6.0.7 and 6.1.3 was vulnerable to a directory traversal attack which could be used to execute arbitrary macros bundled with a document. An attacker could craft a document, which when opened by LibreOffice, would execute a Python method from a script in any arbitrary file system location, specified relative to the LibreOffice install location.

CVSS3: 7.8
debian
почти 7 лет назад

It was found that libreoffice before versions 6.0.7 and 6.1.3 was vuln ...

suse-cvrf
больше 6 лет назад

Security update for LibreOffice

suse-cvrf
больше 6 лет назад

Security update for libreoffice

EPSS

Процентиль: 100%
0.92343
Критический

7.8 High

CVSS3