CVE-2018-6871: Critical severity LibreOffice Libreoffice vulnerability
A flaw was found in libreoffice. Arbitrary remote file disclosure may be achieved by the use of the WEBSERVICE formula in a specially crafted ODS file.
Other sources
LibreOffice before 5.4.5 and 6.x before 6.0.1 allows remote attackers to read arbitrary files via =WEBSERVICE calls in a document, which use the COM.MICROSOFT.WEBSERVICE function.
— Launchpad
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/libreofficeto a version that resolves this vulnerability.Fixed in 5.4.5 - Upgrade
Upgrade
redhat/libreofficeto a version that resolves this vulnerability.Fixed in 6.0.1 - Upgrade
Upgrade
debian/libreofficeto a version that resolves this vulnerability.Fixed in 1:7.0.4-4+deb11u10Fixed in 1:7.0.4-4+deb11u13Fixed in 4:7.4.7-1+deb12u14Fixed in 4:7.4.7-1+deb12u13Fixed in 4:25.2.3-2+deb13u6Fixed in 4:25.2.3-2+deb13u5Fixed in 4:26.2.4.2-2 - Upgrade
Upgrade
libreofficeto a version that resolves this vulnerability.Fixed in 5.4.5 - Upgrade
Upgrade
libreofficeto a version that resolves this vulnerability.Fixed in 6.0.1
Event History
Frequently Asked Questions
What is CVE-2018-6871?
CVE-2018-6871 is a vulnerability in LibreOffice before 5.4.5 and 6.x before 6.0.1 that allows remote attackers to read arbitrary files via WEBSERVICE calls in a document.
How severe is CVE-2018-6871?
CVE-2018-6871 has a severity rating of 9.8, which is considered critical.
Which versions of LibreOffice are affected by CVE-2018-6871?
LibreOffice versions before 5.4.5 and 6.x before 6.0.1 are affected by CVE-2018-6871.
How can I fix CVE-2018-6871?
To fix CVE-2018-6871, you should update LibreOffice to version 5.4.5 or 6.0.1, depending on your current version.
Where can I find more information about CVE-2018-6871?
You can find more information about CVE-2018-6871 on the CVE website (https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-6871) and the Document Foundation blog (https://blog.documentfoundation.org/blog/2018/02/09/early-availability-libreoffice-5-4-5-libreoffice-6-0-1/).