Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.1.10.2018.0271
Category:Mageia Linux Local Security Checks
Title:Mageia: Security Advisory (MGASA-2018-0271)
Summary:The remote host is missing an update for the 'libreoffice' package(s) announced via the MGASA-2018-0271 advisory.
Description:Summary:
The remote host is missing an update for the 'libreoffice' package(s) announced via the MGASA-2018-0271 advisory.

Vulnerability Insight:
The updated packages fix security vulnerabilities:

LibreOffice before 5.4.5 and 6.x before 6.0.1 allows remote attackers to read
arbitrary files via =WEBSERVICE calls in a document, which use the
COM.MICROSOFT.WEBSERVICE function. (CVE-2018-6871)

sot/source/sdstor/stgstrms.cxx in LibreOffice before 5.4.5.1 and 6.x before
6.0.1.1 uses an incorrect integer data type in the StgSmallStrm class, which
allows remote attackers to cause a denial of service (use-after-free with write
access) or possibly have unspecified other impact via a crafted document that
uses the structured storage ole2 wrapper file format. (CVE-2018-10119)

The SwCTBWrapper::Read function in sw/source/filter/ww8/ww8toolbar.cxx in
LibreOffice before 5.4.6.1 and 6.x before 6.0.2.1 does not validate a
customizations index, which allows remote attackers to cause a denial of service
(heap-based buffer overflow with write access) or possibly have unspecified
other impact via a crafted document that contains a certain Microsoft Word
record. (CVE-2018-10120)

An information disclosure vulnerability occurs when LibreOffice 6.0.3 and Apache
OpenOffice Writer 4.1.5 automatically process and initiate an SMB connection
embedded in a malicious file, as demonstrated by
xlink:href=file://192.168.0.2/test.jpg within an office:document-content element
in a .odt XML document. (CVE-2018-10583)

Affected Software/OS:
'libreoffice' package(s) on Mageia 6.

Solution:
Please install the updated package(s).

CVSS Score:
6.8

CVSS Vector:
AV:N/AC:M/Au:N/C:P/I:P/A:P

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2018-10119
Debian Security Information: DSA-4178 (Google Search)
https://www.debian.org/security/2018/dsa-4178
https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=5747
https://gerrit.libreoffice.org/#/c/48751/
https://gerrit.libreoffice.org/#/c/48756/
https://gerrit.libreoffice.org/#/c/48757/
https://gerrit.libreoffice.org/#/c/48758/
https://gerrit.libreoffice.org/gitweb?p=core.git;a=commit;h=fdd41c995d1f719e92c6f083e780226114762f05
https://www.libreoffice.org/about-us/security/advisories/cve-2018-10119/
https://lists.debian.org/debian-lts-announce/2018/04/msg00021.html
RedHat Security Advisories: RHSA-2018:3054
https://access.redhat.com/errata/RHSA-2018:3054
https://usn.ubuntu.com/3883-1/
Common Vulnerability Exposure (CVE) ID: CVE-2018-10120
https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=6173
https://gerrit.libreoffice.org/#/c/49486/
https://gerrit.libreoffice.org/#/c/49499/
https://gerrit.libreoffice.org/#/c/49500/
https://gerrit.libreoffice.org/gitweb?p=core.git;a=commit;h=017fcc2fcd00af17a97bd5463d89662404f57667
https://www.libreoffice.org/about-us/security/advisories/cve-2018-10120/
Common Vulnerability Exposure (CVE) ID: CVE-2018-10583
https://www.exploit-db.com/exploits/44564/
http://seclists.org/fulldisclosure/2020/Oct/26
http://secureyourit.co.uk/wp/2018/05/01/creating-malicious-odt-files/
https://lists.apache.org/thread.html/6c65f22306c36c95e75f8d2b7f49cfcbeb0a4614245c20934612a39d@%3Cdev.openoffice.apache.org%3E
https://lists.apache.org/thread.html/0598708912978b27121b2e380b44a225c706aca882cd1da6a955a0af@%3Cdev.openoffice.apache.org%3E
https://lists.apache.org/thread.html/c8fd59ac77b42aac90eb5c59b87f3ab59b5e0c3bfb4819aa649a2909@%3Cdev.openoffice.apache.org%3E
Common Vulnerability Exposure (CVE) ID: CVE-2018-6871
Debian Security Information: DSA-4111 (Google Search)
https://www.debian.org/security/2018/dsa-4111
https://www.exploit-db.com/exploits/44022/
https://github.com/jollheef/libreoffice-remote-arbitrary-file-disclosure
RedHat Security Advisories: RHSA-2018:0418
https://access.redhat.com/errata/RHSA-2018:0418
RedHat Security Advisories: RHSA-2018:0517
https://access.redhat.com/errata/RHSA-2018:0517
https://usn.ubuntu.com/3579-1/
CopyrightCopyright (C) 2022 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.