CVE-2018-10119Use After Free in Libreoffice

Severity
7.8HIGHNVD
EPSS
0.5%
top 32.19%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 16
Latest updateMay 14

Description

sot/source/sdstor/stgstrms.cxx in LibreOffice before 5.4.5.1 and 6.x before 6.0.1.1 uses an incorrect integer data type in the StgSmallStrm class, which allows remote attackers to cause a denial of service (use-after-free with write access) or possibly have unspecified other impact via a crafted document that uses the structured storage ole2 wrapper file format.

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages7 packages

debiandebian/libreoffice< libreoffice 1:6.0.1-1 (bookworm)
NVDlibreoffice/libreoffice6.0.06.0.1.1+1
Debianlibreoffice/libreoffice< 1:6.0.1-1+3
Ubuntulibreoffice/libreoffice< 1:4.2.8-0ubuntu5.5+1

Also affects: Debian Linux 7.0, 8.0, 9.0, Ubuntu Linux 14.04, 16.04

Patches

🔴Vulnerability Details

3
GHSA
GHSA-4wrw-jm7c-gf3x: sot/source/sdstor/stgstrms2022-05-14
OSV
libreoffice vulnerabilities2019-02-06
OSV
CVE-2018-10119: sot/source/sdstor/stgstrms2018-04-16

📋Vendor Advisories

3
Ubuntu
LibreOffice vulnerabilities2019-02-06
Red Hat
libreoffice: Use-after-free in sdstor/stgstrms.cxx:StgSmallStrm class allows for denial of service with crafted document2018-01-28
Debian
CVE-2018-10119: libreoffice - sot/source/sdstor/stgstrms.cxx in LibreOffice before 5.4.5.1 and 6.x before 6.0....2018

💬Community

2
Bugzilla
CVE-2018-10119 libreoffice: Use after free in sdstor/stgstrms.cxx:StgSmallStrm class allows for denial of service with crafted document [fedora-26]2018-04-20
Bugzilla
CVE-2018-10119 libreoffice: Use-after-free in sdstor/stgstrms.cxx:StgSmallStrm class allows for denial of service with crafted document2018-04-20