CVE-2018-6871 PUBLISHED

LibreOffice before 5.4.5 and 6.x before 6.0.1 allows remote attackers to read arbitrary files via =WEBSERVICE calls in a document, which use the COM.MICROSOFT.WEBSERVICE function.

EPSS 42.68% · 97.4th percentile

Risk Scores

EPSS Score
42.68%
97.4th percentile

Affected Products

VendorProductVersions
Ubuntu:16.04:LTSlibreoffice0, 1:5.0.2-0ubuntu1, 1:5.0.2-0ubuntu2
Ubuntu:14.04:LTSlibreoffice1:4.2.8-0ubuntu3, 1:4.2.8-0ubuntu4, 0

Timeline

References

Open in Interactive Console →