RHSA-2018:0418Vendor advisory
https://access.redhat.com/errata/RHSA-2018:0418 CVE-2018-6871
CRITICAL
LibreOffice < 6.0.1 - '=WEBSERVICE' Remote Arbitrary File Disclosure
Record summary
CVE-2018-6871 has a selected CVSS score of 9.8 (critical); EIP currently links 1 catalogued exploit.
Description
LibreOffice before 5.4.5 and 6.x before 6.0.1 allows remote attackers to read arbitrary files via =WEBSERVICE calls in a document, which use the COM.MICROSOFT.WEBSERVICE function.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBLibreOffice < 6.0.1 - '=WEBSERVICE' Remote Arbitrary File DisclosureExploitDB exploitby Mikhail KlementevNot analyzed1 file
References
9RHSA-2018:0517Vendor advisory
https://access.redhat.com/errata/RHSA-2018:0517 cgit.freedesktop.orgConfirmation
https://cgit.freedesktop.org/libreoffice/core/commit?h=libreoffice-5-4-5&id=a916fc0c0e0e8b10cb4158fa0fa173fe205d434a github.com
https://github.com/jollheef/libreoffice-remote-arbitrary-file-disclosure nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2018-6871 USN-3579-1Vendor advisory
https://usn.ubuntu.com/3579-1 DSA-4111Vendor advisory
https://www.debian.org/security/2018/dsa-4111 44022exploit
https://www.exploit-db.com/exploits/44022 libreoffice.orgConfirmation
https://www.libreoffice.org/about-us/security/advisories/cve-2018-1055