vendor:
LibreOffice
by:
jollheef, Ronnie Goodrich, Andrew Krasichkov
9.8
CVSS
CRITICAL
COM.MICROSOFT.WEBSERVICE Function Vulnerability
20
CWE
Product Name: LibreOffice
Affected Version From: Prior to 5.4.5/6.0.1
Affected Version To: Prior to 5.4.5/6.0.1
Patch Exists: YES
Related CWE: CVE-2018-6871
CPE: a:documentfoundation:libreoffice
Metasploit:
https://www.rapid7.com/db/vulnerabilities/ubuntu-usn-3579-2/, https://www.rapid7.com/db/vulnerabilities/gentoo-linux-cve-2018-6871/, https://www.rapid7.com/db/vulnerabilities/alpine-linux-cve-2018-6871/, https://www.rapid7.com/db/vulnerabilities/oracle_linux-cve-2018-6871/, https://www.rapid7.com/db/vulnerabilities/freebsd-cve-2018-6871/, https://www.rapid7.com/db/vulnerabilities/centos_linux-cve-2018-6871/, https://www.rapid7.com/db/vulnerabilities/suse-cve-2018-6871/, https://www.rapid7.com/db/vulnerabilities/debian-cve-2018-6871/, https://www.rapid7.com/db/vulnerabilities/redhat_linux-cve-2018-6871/, https://www.rapid7.com/db/vulnerabilities/ubuntu-cve-2018-6871/
Other Scripts:
N/A
Platforms Tested: GNU/Linux, MS Windows, macOS
2018
LibreOffice COM.MICROSOFT.WEBSERVICE Function Vulnerability
LibreOffice supports COM.MICROSOFT.WEBSERVICE function which is required to obtain data by URL. This function can be used to read files and send files with keys, passwords and anything else. It affects LibreOffice prior to 5.4.5/6.0.1 in all operation systems (GNU/Linux, MS Windows, macOS etc.) and may be embedded in almost all formats supporting by LO.
Mitigation:
Upgrade to LibreOffice 5.4.5/6.0.1 or later