CVE-2018-16858: Path Traversal
A flaw was found in libreoffice. If a document does not contain macros/scripts, but references a pre-installed macro/script execution of those macros/scripts, execution is allowed without warning bypassing normal behavior.
Other sources
It was found that libreoffice before versions 6.0.7 and 6.1.3 was vulnerable to a directory traversal attack which could be used to execute arbitrary macros bundled with a document. An attacker could craft a document, which when opened by LibreOffice, would execute a Python method from a script in any arbitrary file system location, specified relative to the LibreOffice install location.
— Launchpad
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2018-16858?
CVE-2018-16858 is a vulnerability in LibreOffice that allows for a directory traversal attack, potentially leading to the execution of arbitrary macros.
How can this vulnerability be exploited?
This vulnerability can be exploited by crafting a document that, when opened by LibreOffice, executes a Python method from a script in a malicious document.
What is the severity of CVE-2018-16858?
The severity of CVE-2018-16858 is rated as critical with a CVSS score of 9.8.
Which versions of LibreOffice are affected by CVE-2018-16858?
LibreOffice versions before 6.0.7 and 6.1.3 are affected by CVE-2018-16858.
How can I mitigate the vulnerability in LibreOffice?
To mitigate the vulnerability, it is recommended to update to LibreOffice versions 6.0.7 or 6.1.3, depending on the version in use.