Information disclosure in LibreOffice - CVE-2018-10583

 

Information disclosure in LibreOffice - CVE-2018-10583

Published: May 21, 2018 / Updated: June 17, 2021


Vulnerability identifier: #VU12887
CSH Severity: Low
CVSS v4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-10583
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: Public exploit is available

Vulnerability details

The vulnerability allows a remote attacker to obtain potentially sensitive information on the target system.

The weakness exists due to automatic processing and initiating of an SMB connection embedded in a malicious file. A remote attacker can trick the victim into opening a specially crafted file and gain access to potentially sensitive information.


Affected software

LibreOffice
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for Power
Opensuse
Fedora
libreoffice

How to mitigate CVE-2018-10583

The vulnerability is addressed in the following versions: 5.4.7, 6.0.4.

libreoffice - addressed in versions 5.4.6.2-6.fc27, 6.0.3.2-9.fc28

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins