CVE-2018-10583
An information disclosure vulnerability occurs when LibreOffice 6.0.3 and Apache OpenOffice Writer 4.1.5 automatically process and initiate an SMB connection embedded in a malicious file, as demonstrated by xlink:href=file://192.168.0.2/test.jpg within an office:document-content element in a .odt XML document.
- Affected products
- Apache Openoffice, Debian, Libreoffice, Openoffice, Red Hat, Suse, Ubuntu
- Libreoffice
- = 6.0.3
- Fix
- Available
- CVSS 3.0
- 7.5 HIGH
- EPSS
- 79.0% (100th percentile)
- Weakness
- CWE-200
- NVD status
- Modified
- Published
- 2018-05-01
CVE-2018-10583 at NVD
6 known exploits for CVE-2018-10583
Proof-of-concept code and exploit modules indexed by Sploitus
LibreOffice 6.03 /Apache OpenOffice 4.1.5 Malicious ODT File Generator
BigBlueButton 2.2.25 File Disclosure / Server-Side Request Forgery
LibreOffice 6.03 /Apache OpenOffice 4.1.5 Malicious ODT File Generator
LibreOffice 6.0.3 / OpenOffice 4.1.5 Information Disclosure
LibreOffice / Open Office - .odt Information Disclosure Exploit
LibreOffice/Open Office - '.odt' Information Disclosure