CVE-2018-6871
published 2018-02-09CVE-2018-6871: LibreOffice before 5.4.5 and 6.x before 6.0.1 allows remote attackers to read arbitrary files via =WEBSERVICE calls in a document, which use the…
PriorityP267critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EXPLOIT
EPSS
23.20%
97.5th percentile
LibreOffice before 5.4.5 and 6.x before 6.0.1 allows remote attackers to read arbitrary files via =WEBSERVICE calls in a document, which use the COM.MICROSOFT.WEBSERVICE function.
Affected
26 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | libreoffice | < libreoffice 1:6.0.1-1 (bookworm) | libreoffice 1:6.0.1-1 (bookworm) |
| libreoffice | libreoffice | < 5.4.5 | 5.4.5 |
| libreoffice | libreoffice | — | — |
| libreoffice | libreoffice | >= 0 < 1:6.0.1-1 | 1:6.0.1-1 |
| libreoffice | libreoffice | >= 0 < 1:6.0.1-1 | 1:6.0.1-1 |
| libreoffice | libreoffice | >= 0 < 1:6.0.1-1 | 1:6.0.1-1 |
| libreoffice | libreoffice | >= 0 < 1:6.0.1-1 | 1:6.0.1-1 |
| libreoffice | libreoffice | >= 0 < 1:4.2.8-0ubuntu5.3 | 1:4.2.8-0ubuntu5.3 |
| libreoffice | libreoffice | >= 0 < 1:5.1.6~rc2-0ubuntu1~xenial3 | 1:5.1.6~rc2-0ubuntu1~xenial3 |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_eus | — | — |
| redhat | enterprise_linux_server_eus | — | — |
| redhat | enterprise_linux_server_eus | — | — |
| redhat | enterprise_linux_server_tus | — | — |
| redhat | enterprise_linux_server_tus | — | — |
| redhat | enterprise_linux_workstation | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Detect LibreOffice documents (ODS files) containing WEBSERVICE or COM.MICROSOFT.WEBSERVICE formula calls, which can be used to exfiltrate arbitrary local files to a remote attacker-controlled server. ↗
- →Monitor outbound HTTP requests originating from LibreOffice processes (e.g., soffice, soffice.bin) to unexpected external hosts, which may indicate WEBSERVICE formula exfiltration in progress. ↗
- →Inspect ODS/ODF spreadsheet XML content for the string 'WEBSERVICE' or 'COM.MICROSOFT.WEBSERVICE' in formula cells as a static file-based detection method. ↗
- ·Red Hat Enterprise Linux 8 ships a version of LibreOffice that is not affected by this CVE; detections targeting RHEL 8 endpoints may produce false positives if not version-gated. ↗
- ·The USN-3579-1 patch introduced a regression preventing LibreOffice from opening documents from certain locations outside the user's home directory; USN-3579-3 corrects this. Ensure the regression-fix update is applied alongside the security fix. ↗
CVSS provenance
nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_redhat9.8CRITICAL
vendor_ubuntu9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
LibreOffice regression
vendor_ubuntu·2018-03-07·CVSS 9.8
[CRITICAL] LibreOffice regression
Title: LibreOffice regression
Summary: USN-3579-1 caused a regression in LibreOffice.
USN-3579-1 fixed a vulnerability in LibreOffice. After upgrading, it was
no longer possible for LibreOffice to open documents from certain
locations outside of the user's home directory. This update fixes the
problem.
We apologize for the inconvenience.
Original advisory details:
It was discovered that =WEBSERVICE calls in a document could be used to
read arbitrary files. If a user were tricked in to opening a specially
crafted document, a remote attacker could exploit this to obtain sensitive
information. (CVE-2018-6871)
Instructions: After a standard system update you need to restart LibreOffice to make
all the necessary changes.
Ubuntu
LibreOffice vulnerability
vendor_ubuntu·2018-02-21·CVSS 9.8
CVE-2018-6871 [CRITICAL] LibreOffice vulnerability
Title: LibreOffice vulnerability
Summary: LibreOffice would allow unintended access to files over the network.
It was discovered that =WEBSERVICE calls in a document could be used to
read arbitrary files. If a user were tricked in to opening a specially
crafted document, a remote attacker could exploit this to obtain sensitive
information. (CVE-2018-6871)
Instructions: After a standard system update you need to restart LibreOffice to make
all the necessary changes.
Red Hat
libreoffice: Remote arbitrary file disclosure vulnerability via WEBSERVICE formula
vendor_redhat·2018-02-12·CVSS 9.8
CVE-2018-6871 [CRITICAL] CWE-200 libreoffice: Remote arbitrary file disclosure vulnerability via WEBSERVICE formula
libreoffice: Remote arbitrary file disclosure vulnerability via WEBSERVICE formula
LibreOffice before 5.4.5 and 6.x before 6.0.1 allows remote attackers to read arbitrary files via =WEBSERVICE calls in a document, which use the COM.MICROSOFT.WEBSERVICE function.
A flaw was found in libreoffice before 5.4.5 and before 6.0.1. Arbitrary remote file disclosure may be achieved by the use of the WEBSERVICE formula in a specially crafted ODS file.
Package: libreoffice (Red Hat Enterprise Linux 8) - Not affected
Debian
CVE-2018-6871: libreoffice - LibreOffice before 5.4.5 and 6.x before 6.0.1 allows remote attackers to read ar...
vendor_debian·2018·CVSS 9.8
CVE-2018-6871 [CRITICAL] CVE-2018-6871: libreoffice - LibreOffice before 5.4.5 and 6.x before 6.0.1 allows remote attackers to read ar...
LibreOffice before 5.4.5 and 6.x before 6.0.1 allows remote attackers to read arbitrary files via =WEBSERVICE calls in a document, which use the COM.MICROSOFT.WEBSERVICE function.
Scope: local
bookworm: resolved (fixed in 1:6.0.1-1)
bullseye: resolved (fixed in 1:6.0.1-1)
forky: resolved (fixed in 1:6.0.1-1)
sid: resolved (fixed in 1:6.0.1-1)
trixie: resolved (fixed in 1:6.0.1-1)
GHSA
GHSA-4xgr-65gv-68q9: LibreOffice before 5
ghsa_unreviewed·2022-05-13
CVE-2018-6871 [CRITICAL] GHSA-4xgr-65gv-68q9: LibreOffice before 5
LibreOffice before 5.4.5 and 6.x before 6.0.1 allows remote attackers to read arbitrary files via =WEBSERVICE calls in a document, which use the COM.MICROSOFT.WEBSERVICE function.
OSV
libreoffice vulnerability
osv·2018-02-21·CVSS 9.8
CVE-2018-6871 [CRITICAL] libreoffice vulnerability
libreoffice vulnerability
It was discovered that =WEBSERVICE calls in a document could be used to
read arbitrary files. If a user were tricked in to opening a specially
crafted document, a remote attacker could exploit this to obtain sensitive
information. (CVE-2018-6871)
OSV
CVE-2018-6871: LibreOffice before 5
osv·2018-02-09·CVSS 9.8
CVE-2018-6871 [CRITICAL] CVE-2018-6871: LibreOffice before 5
LibreOffice before 5.4.5 and 6.x before 6.0.1 allows remote attackers to read arbitrary files via =WEBSERVICE calls in a document, which use the COM.MICROSOFT.WEBSERVICE function.
No detection rules found.
Bugzilla
CVE-2018-6871 libreoffice: Remote arbitrary file disclosure vulnerability via WEBSERVICE formula [fedora-all]
bugzilla·2018-02-14·CVSS 9.8
CVE-2018-6871 [CRITICAL] CVE-2018-6871 libreoffice: Remote arbitrary file disclosure vulnerability via WEBSERVICE formula [fedora-all]
CVE-2018-6871 libreoffice: Remote arbitrary file disclosure vulnerability via WEBSERVICE formula [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue aff
Bugzilla
CVE-2018-6871 libreoffice: Remote arbitrary file disclosure vulnerability via WEBSERVICE formula
bugzilla·2018-02-07·CVSS 9.8
CVE-2018-6871 [CRITICAL] CVE-2018-6871 libreoffice: Remote arbitrary file disclosure vulnerability via WEBSERVICE formula
CVE-2018-6871 libreoffice: Remote arbitrary file disclosure vulnerability via WEBSERVICE formula
A flaw was found in libreoffice. Arbitrary remote file disclosure may be achieved by the use of the WEBSERVICE formula in a specially crafted ODS file.
Discussion:
Created libreoffice tracking bugs for this issue:
Affects: fedora-all [bug 1545023]
---
Note that libreoffice upstream refers to this as CVE-2018-1055, while MITRE calls it CVE-2018-6871. Both identifiers refer to the same issue.
---
External References:
https://github.com/jollheef/libreoffice-remote-arbitrary-file-disclosure
https://www.libreoffice.org/about-us/security/advisories/cve-2018-1055/
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2018:0418 https://access.redh
https://access.redhat.com/errata/RHSA-2018:0418https://access.redhat.com/errata/RHSA-2018:0517https://cgit.freedesktop.org/libreoffice/core/commit/?h=libreoffice-5-4-5&id=a916fc0c0e0e8b10cb4158fa0fa173fe205d434ahttps://github.com/jollheef/libreoffice-remote-arbitrary-file-disclosurehttps://usn.ubuntu.com/3579-1/https://www.debian.org/security/2018/dsa-4111https://www.exploit-db.com/exploits/44022/https://www.libreoffice.org/about-us/security/advisories/cve-2018-1055/https://access.redhat.com/errata/RHSA-2018:0418https://access.redhat.com/errata/RHSA-2018:0517https://cgit.freedesktop.org/libreoffice/core/commit/?h=libreoffice-5-4-5&id=a916fc0c0e0e8b10cb4158fa0fa173fe205d434ahttps://github.com/jollheef/libreoffice-remote-arbitrary-file-disclosurehttps://usn.ubuntu.com/3579-1/https://www.debian.org/security/2018/dsa-4111https://www.exploit-db.com/exploits/44022/https://www.libreoffice.org/about-us/security/advisories/cve-2018-1055/
2018-02-09
Published