CVE-2018-10583
Last modified
CVE-2018-10583 is a vulnerability of currently unknown severity. An information disclosure vulnerability occurs when LibreOffice 6.0.3 and Apache OpenOffice Writer 4.1.5 automatically process and initiate an SMB connection embedded in a malicious file, as demonstrated by xlink:href=file://192.168.0.2/test.jpg within an office:document-content element in a .odt XML document.. EPSS estimates a 78.91% chance of exploitation in the next 30 days.
Description
An information disclosure vulnerability occurs when LibreOffice 6.0.3 and Apache OpenOffice Writer 4.1.5 automatically process and initiate an SMB connection embedded in a malicious file, as demonstrated by xlink:href=file://192.168.0.2/test.jpg within an office:document-content element in a .odt XML document.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Libreoffice | Libreoffice | 6.0.3 |
| Apache | Openoffice | 4.1.5 |
| Debian | Debian Linux | 7.0 |
| Debian | Debian Linux | 8.0 |
| Debian | Debian Linux | 9.0 |
| Redhat | Enterprise Linux Desktop | 7.0 |
| Redhat | Enterprise Linux Server | 7.0 |
| Redhat | Enterprise Linux Workstation | 7.0 |
| Canonical | Ubuntu Linux | 14.04 |
| Canonical | Ubuntu Linux | 16.04 |
References
- http://secureyourit.co.uk/wp/2018/05/01/creating-malicious-odt-files/Exploit, Mitigation, Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:3054Third Party Advisory
- https://security-tracker.debian.org/tracker/CVE-2018-10583Issue Tracking, Third Party Advisory
- https://usn.ubuntu.com/3883-1/Third Party Advisory
- https://www.exploit-db.com/exploits/44564/Exploit, Third Party Advisory, VDB Entry
- http://secureyourit.co.uk/wp/2018/05/01/creating-malicious-odt-files/Exploit, Mitigation, Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:3054Third Party Advisory
- https://security-tracker.debian.org/tracker/CVE-2018-10583Issue Tracking, Third Party Advisory
- https://usn.ubuntu.com/3883-1/Third Party Advisory
- https://www.exploit-db.com/exploits/44564/Exploit, Third Party Advisory, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-10583?
How severe is CVE-2018-10583?
How do I fix CVE-2018-10583?
Are you affected by CVE-2018-10583?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
