Path traversal in LibreOffice - CVE-2018-16858
Published: February 4, 2019 / Updated: June 17, 2021
Vulnerability details
The vulnerability allows a remote attacker to perform directory traversal attacks.
The vulnerability exists due to input validation error. A remote attacker can trick the victim into opening a specially crafted Office file, conduct path traversal attack and execute a python method from a script in any arbitrary file system location
Affected software
libreoffice (Debian package)
libreoffice
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Opensuse
Fedora
How to mitigate CVE-2018-16858
libreoffice (Debian package) - update to 1:5.2.7-1+deb9u5
libreoffice - update to 6.0.7.3-1.fc28
Links to Public Exploits and PoC-codes
- Exploit #6080 - LibreOffice < 6.0.7 / 6.1.3 - Macro Code Execution (Metasploit) (June 17, 2021)
- Exploit #6004 - LibreOffice < 6.2.6 Macro - Python Code Execution (Metasploit) (June 17, 2021)
- Exploit #2347 - libreofficeExploit1 (CVE-2018-16858 exploit implementation) (April 7, 2020)
- Exploit #1558 - LibreOffice Macro Code Execution (March 18, 2020)