First published: Sun Nov 18 2018(Updated: )
When loading a document with Apache Open Office 4.1.5 and earlier with smaller end line termination than the operating system uses, the defect occurs. In this case OpenOffice runs into an Arithmetic Overflow at a string length calculation.
Credit: security@apache.org security@apache.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apache OpenOffice | <=4.1.5 | |
Canonical Ubuntu Linux | =14.04 | |
Canonical Ubuntu Linux | =16.04 | |
ubuntu/libreoffice | <1:4.2.8-0ubuntu5.5 | 1:4.2.8-0ubuntu5.5 |
ubuntu/libreoffice | <1:5.0.3~ | 1:5.0.3~ |
debian/libreoffice | 1:7.0.4-4+deb11u9 1:7.0.4-4+deb11u10 4:7.4.7-1+deb12u3 4:7.4.7-1+deb12u4 4:24.2.5-3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-11790 is a vulnerability that occurs when loading a document with Apache Open Office 4.1.5 and earlier with smaller end line termination than the operating system uses, leading to an Arithmetic Overflow at a string length calculation.
The software affected by CVE-2018-11790 includes Apache OpenOffice 4.1.5 and earlier versions and certain versions of LibreOffice on Ubuntu and Debian.
CVE-2018-11790 has a severity level of 7.8, which is considered high.
To fix CVE-2018-11790, users should update Apache OpenOffice to version 4.1.6 or later and ensure they are running the latest version of LibreOffice on Ubuntu and Debian.
More information about CVE-2018-11790 can be found on the MITRE CVE database and the official security notices from OpenWall and Ubuntu.