First published: Wed Feb 06 2019(Updated: )
It was discovered that LibreOffice incorrectly handled certain document files. If a user were tricked into opening a specially crafted document, a remote attacker could cause LibreOffice to crash, and possibly execute arbitrary code. (CVE-2018-10119, CVE-2018-10120, CVE-2018-11790) It was discovered that LibreOffice incorrectly handled embedded SMB connections in document files. If a user were tricked in to opening a specially crafted document, a remote attacker could possibly exploit this to obtain sensitive information. (CVE-2018-10583) Alex Inführ discovered that LibreOffice incorrectly handled embedded scripts in document files. If a user were tricked into opening a specially crafted document, a remote attacker could possibly execute arbitrary code. (CVE-2018-16858)
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
ubuntu/libreoffice-core | <1:5.1.6~rc2-0ubuntu1~xenial6 | 1:5.1.6~rc2-0ubuntu1~xenial6 |
Ubuntu Ubuntu | =16.04 | |
All of | ||
ubuntu/libreoffice-core | <1:4.2.8-0ubuntu5.5 | 1:4.2.8-0ubuntu5.5 |
Ubuntu Ubuntu | =14.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Contains the following vulnerabilities)
The vulnerability ID for this advisory is CVE-2018-10119, CVE-2018-10120, and CVE-2018-11790.
The affected software version is LibreOffice 5.1.6~rc2-0ubuntu1~xenial6 on Ubuntu 16.04 and LibreOffice 4.2.8-0ubuntu5.5 on Ubuntu 14.04.
This vulnerability could allow a remote attacker to crash LibreOffice and possibly execute arbitrary code.
To fix this vulnerability, update to the latest version of LibreOffice.
You can find more information about this vulnerability on the Ubuntu Security website.