First published: Sun Apr 15 2018(Updated: )
LibreOffice before versions 5.4.6.1 and 6.0.2.1 has a missing bounds check in sw/source/filter/ww8/ww8toolbar.cxx:SwCTBWrapper::Read() allowing for an out of bounds write. An attacker could exploit this to cause a denial of service via crafted document. External Reference: <a href="https://www.libreoffice.org/about-us/security/advisories/cve-2018-10120/">https://www.libreoffice.org/about-us/security/advisories/cve-2018-10120/</a> Additional Reference: <a href="https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=6173">https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=6173</a> Upstream Patches: <a href="https://gerrit.libreoffice.org/gitweb?p=core.git;a=commit;h=017fcc2fcd00af17a97bd5463d89662404f57667">https://gerrit.libreoffice.org/gitweb?p=core.git;a=commit;h=017fcc2fcd00af17a97bd5463d89662404f57667</a> <a href="https://gerrit.libreoffice.org/#/c/49486/">https://gerrit.libreoffice.org/#/c/49486/</a> <a href="https://gerrit.libreoffice.org/#/c/49499/">https://gerrit.libreoffice.org/#/c/49499/</a> <a href="https://gerrit.libreoffice.org/#/c/49500/">https://gerrit.libreoffice.org/#/c/49500/</a>
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/libreoffice | <5.4.6.1 | 5.4.6.1 |
redhat/libreoffice | <6.0.2.1 | 6.0.2.1 |
ubuntu/libreoffice | <1:4.2.8-0ubuntu5.5 | 1:4.2.8-0ubuntu5.5 |
ubuntu/libreoffice | <1:5.1.6~ | 1:5.1.6~ |
debian/libreoffice | 1:7.0.4-4+deb11u9 1:7.0.4-4+deb11u10 4:7.4.7-1+deb12u3 4:7.4.7-1+deb12u4 4:24.2.5-3 | |
Debian Debian Linux | =7.0 | |
Debian Debian Linux | =8.0 | |
Debian Debian Linux | =9.0 | |
The Document Foundation LibreOffice | <5.4.6.1 | |
The Document Foundation LibreOffice | >=6.0.0<6.0.2.1 | |
redhat enterprise Linux desktop | =7.0 | |
redhat enterprise Linux server | =7.0 | |
redhat enterprise Linux workstation | =7.0 | |
Ubuntu Linux | =14.04 | |
Ubuntu Linux | =16.04 |
https://gerrit.libreoffice.org/gitweb?p=core.git;a=commit;h=017fcc2fcd00af17a97bd5463d89662404f57667
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this issue is CVE-2018-10120.
CVE-2018-10120 has a severity rating of 7.8 (High).
CVE-2018-10120 affects LibreOffice versions before 5.4.6.1 and 6.x before 6.0.2.1.
CVE-2018-10120 can be exploited by remote attackers to cause a denial of service (heap-based buffer overflow with write access) or possibly have unspecified impacts.
Remedies are available for CVE-2018-10120, with specific version updates provided by Red Hat, Ubuntu, Debian, and LibreOffice.