CVE-2018-10583 PUBLISHED

An information disclosure vulnerability occurs when LibreOffice 6.0.3 and Apache OpenOffice Writer 4.1.5 automatically process and initiate an SMB connection embedded in a malicious file, as demonstrated by xlink:href=file://192.168.0.2/test.jpg within an office:document-content element in a .odt XML document.

EPSS 71.89% · 98.7th percentile

Risk Scores

EPSS Score
71.89%
98.7th percentile

Affected Products

VendorProductVersions
Ubuntu:14.04:LTSlibreoffice0, 1:4.1.2~rc3-0ubuntu1, 1:4.1.2~rc3-0ubuntu2
Ubuntu:16.04:LTSlibreoffice0, 1:5.0.2-0ubuntu1, 1:5.0.2-0ubuntu2

Timeline

References

Open in Interactive Console →