Path traversal in LibreOffice - CVE-2018-16858
Published: February 4, 2019 / Updated: June 17, 2021
LibreOffice
libreoffice (Debian package)
libreoffice
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Opensuse
Fedora
Detailed vulnerability description
The vulnerability allows a remote attacker to perform directory traversal attacks.
The vulnerability exists due to input validation error. A remote attacker can trick the victim into opening a specially crafted Office file, conduct path traversal attack and execute a python method from a script in any arbitrary file system location