Information disclosure in LibreOffice - CVE-2018-10583
Published: May 21, 2018 / Updated: June 17, 2021
Vulnerability details
The vulnerability allows a remote attacker to obtain potentially sensitive information on the target system.
The weakness exists due to automatic processing and initiating of an SMB connection embedded in a malicious file. A remote attacker can trick the victim into opening a specially crafted file and gain access to potentially sensitive information.
Affected software
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for Power
Opensuse
Fedora
libreoffice
How to mitigate CVE-2018-10583
Links to Public Exploits and PoC-codes
- Exploit #5644 - BigBlueButton 2.2.25 - Arbitrary File Disclosure and Server-Side Request Forgery (June 17, 2021)
- Exploit #1932 - CVE-2018-10583 (An information disclosure vulnerability occurs when LibreOffice 6.0.3 and Apache OpenOffice Writer 4.1.5 automatically process and initiate an SMB connection embedded in a malicious file, as demonstrated by "xlink:href=file://192.168.0.2/t (March 18, 2020)
- Exploit #76 - LibreOffice 6.03 /Apache OpenOffice 4.1.5 Malicious ODT File Generator (March 18, 2020)