cbcvebase.
CVE-2018-6871
published 2018-02-09

CVE-2018-6871: LibreOffice before 5.4.5 and 6.x before 6.0.1 allows remote attackers to read arbitrary files via =WEBSERVICE calls in a document, which use the…

critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EXPLOIT
LibreOffice before 5.4.5 and 6.x before 6.0.1 allows remote attackers to read arbitrary files via =WEBSERVICE calls in a document, which use the COM.MICROSOFT.WEBSERVICE function.

Affected

26 ranges· showing 25
VendorProductVersion rangeFixed in
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debiandebian_linux
debianlibreoffice< libreoffice 1:6.0.1-1 (bookworm)libreoffice 1:6.0.1-1 (bookworm)
libreofficelibreoffice< 5.4.55.4.5
libreofficelibreoffice
libreofficelibreoffice>= 0 < 1:6.0.1-11:6.0.1-1
libreofficelibreoffice>= 0 < 1:6.0.1-11:6.0.1-1
libreofficelibreoffice>= 0 < 1:6.0.1-11:6.0.1-1
libreofficelibreoffice>= 0 < 1:6.0.1-11:6.0.1-1
libreofficelibreoffice>= 0 < 1:4.2.8-0ubuntu5.31:4.2.8-0ubuntu5.3
libreofficelibreoffice>= 0 < 1:5.1.6~rc2-0ubuntu1~xenial31:5.1.6~rc2-0ubuntu1~xenial3
redhatenterprise_linux_desktop
redhatenterprise_linux_desktop
redhatenterprise_linux_server
redhatenterprise_linux_server
redhatenterprise_linux_server_aus
redhatenterprise_linux_server_aus
redhatenterprise_linux_server_eus
redhatenterprise_linux_server_eus
redhatenterprise_linux_server_eus
redhatenterprise_linux_server_tus
redhatenterprise_linux_server_tus
redhatenterprise_linux_workstation

CVSS provenance

nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
osv9.8CRITICAL