CVE-2018-10583

Source
https://nvd.nist.gov/vuln/detail/CVE-2018-10583
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-10583.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2018-10583
Related
Published
2018-05-01T16:29:00Z
Modified
2024-09-03T02:12:40.393598Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
Summary
[none]
Details

An information disclosure vulnerability occurs when LibreOffice 6.0.3 and Apache OpenOffice Writer 4.1.5 automatically process and initiate an SMB connection embedded in a malicious file, as demonstrated by xlink:href=file://192.168.0.2/test.jpg within an office:document-content element in a .odt XML document.

References

Affected packages

Debian:11 / libreoffice

Package

Name
libreoffice
Purl
pkg:deb/debian/libreoffice?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1:7.*

1:7.0.4-4
1:7.0.4-4+deb11u1~bpo10+1
1:7.0.4-4+deb11u1
1:7.0.4-4+deb11u2
1:7.0.4-4+deb11u3~bpo10+1
1:7.0.4-4+deb11u3
1:7.0.4-4+deb11u4~bpo10+1
1:7.0.4-4+deb11u4
1:7.0.4-4+deb11u5
1:7.0.4-4+deb11u6
1:7.0.4-4+deb11u7
1:7.0.4-4+deb11u8
1:7.0.4-4+deb11u9
1:7.0.4-4+deb11u10
1:7.1.0~alpha1-1
1:7.1.0~beta1-1
1:7.1.0~rc1-1
1:7.1.0~rc2-1
1:7.1.0~rc3-1
1:7.1.1~rc1-1
1:7.1.1~rc2-1
1:7.1.1~rc2-2
1:7.1.2~rc1-1
1:7.1.2~rc2-1
1:7.1.3~rc1-1
1:7.1.3~rc2-1
1:7.1.4~rc1-1
1:7.1.4~rc1-2
1:7.1.4~rc2-1
1:7.1.5-1
1:7.1.5-2~bpo11+1
1:7.1.5-2
1:7.2.0~beta1-1
1:7.2.0~beta1-2
1:7.2.0~beta1-3
1:7.2.0~beta1-4
1:7.2.0~rc1-1
1:7.2.0~rc2-1
1:7.2.0~rc2-2
1:7.2.0~rc2-3
1:7.2.0~rc2-4
1:7.2.0~rc3-1
1:7.2.0~rc4-1
1:7.2.0-1
1:7.2.0-2
1:7.2.0-3
1:7.2.1~rc1-1
1:7.2.1~rc1-2
1:7.2.1~rc2-1
1:7.2.1-1
1:7.2.1-2
1:7.2.1-3~bpo11+1
1:7.2.1-3
1:7.2.1-4
1:7.2.2~rc1-1
1:7.2.2~rc2-1
1:7.2.2-1~bpo11+1
1:7.2.2-1
1:7.2.3-1
1:7.2.3-2~bpo11+1
1:7.2.3-2
1:7.2.4-1
1:7.2.4-2
1:7.2.4-3
1:7.2.5-1~bpo11+1
1:7.2.5-1
1:7.3.0~alpha1-1
1:7.3.0~alpha1-2
1:7.3.0~alpha1-3
1:7.3.0~alpha1-4
1:7.3.0~alpha1-5
1:7.3.0~alpha1-6
1:7.3.0~beta1-1
1:7.3.0~beta1-2
1:7.3.0~beta1-3
1:7.3.0~beta1-4
1:7.3.0~rc1-1
1:7.3.0~rc1-2
1:7.3.0~rc2-1
1:7.3.0~rc2-2
1:7.3.0~rc2-3
1:7.3.0-1~bpo11+1
1:7.3.0-1
1:7.3.1~rc1-1
1:7.3.1-1~bpo11+1
1:7.3.1-1
1:7.3.2~rc2-1
1:7.3.3~rc1-1
1:7.3.3~rc1-2~bpo11+1
1:7.3.3~rc1-2
1:7.3.3~rc2-1
1:7.3.4~rc1-1~bpo11+1
1:7.3.4~rc1-1
1:7.3.4~rc2-1~bpo11+1
1:7.3.4~rc2-1
1:7.3.5~rc1-1~bpo11+1
1:7.3.5~rc1-1~bpo11+2
1:7.3.5~rc1-1
1:7.3.5~rc2-1~bpo11+1
1:7.3.5~rc2-1
1:7.4.0~alpha1-1
1:7.4.0~alpha1-2
1:7.4.0~beta1-1
1:7.4.0~beta1-2
1:7.4.0~beta1-3
1:7.4.0~beta1-4
1:7.4.0~rc1-1
1:7.4.0~rc1-2
1:7.4.0~rc1-3
1:7.4.0~rc2-1
1:7.4.0~rc2-2
1:7.4.0~rc2-3
1:7.4.0~rc3-1
1:7.4.1~rc1-1
1:7.4.1~rc1-2~bpo11+1
1:7.4.1~rc1-2
1:7.4.1~rc1-3~bpo11+1
1:7.4.1~rc1-3
1:7.4.1~rc2-1
1:7.4.1~rc2-2
1:7.4.1~rc2-3~bpo11+1
1:7.4.1~rc2-3
1:7.4.1-1~bpo11+1
1:7.4.1-1~bpo11+2
1:7.4.1-1
1:7.4.1-2
1:7.4.2~rc1-1
1:7.4.2~rc1-2
1:7.4.2~rc2-1
1:7.4.2~rc3-1
1:7.4.2-1
1:7.4.2-2~bpo11+1
1:7.4.2-2~bpo11+2
1:7.4.2-2
1:7.4.2-3
1:7.4.2-4
1:7.4.3~rc1-1
1:7.4.3~rc1-2
1:7.4.3~rc2-1
1:7.4.3~rc2-2
1:7.4.3-1
1:7.4.3-2~bpo11+1
1:7.4.3-2
1:7.4.3-3
1:7.4.4~rc1-1
1:7.4.4~rc2-1
1:7.4.4~rc2-2~bpo11+1
1:7.4.4~rc2-2~bpo11+2
1:7.4.4~rc2-2~bpo11+3
1:7.4.4~rc2-2
1:7.4.4-1
1:7.4.4-2
1:7.4.4-3
1:7.5.0~alpha1-1
1:7.5.0~alpha1-2
1:7.5.0~beta1-1
1:7.5.0~rc1-1
1:7.5.0~rc1-2
1:7.5.0~rc2-1
1:7.5.0~rc2-2
1:7.5.0~rc2-3

2:7.*

2:7.4.4-4
2:7.4.4-5
2:7.4.4-6
2:7.5.0~rc2-4

3:7.*

3:7.5.0~rc2-5
3:7.5.0~rc2-6

4:7.*

4:7.4.4-7
4:7.4.4-8
4:7.4.5-1~bpo11+1
4:7.4.5-1
4:7.4.5-2
4:7.4.5-3~bpo11+1
4:7.4.5-3
4:7.4.7-1~bpo11+1
4:7.4.7-1
4:7.5.0~rc2-7
4:7.5.0~rc3-1
4:7.5.1~rc1-1
4:7.5.1~rc2-1
4:7.5.2~rc1-1
4:7.5.2~rc2-1
4:7.5.3~rc1-1
4:7.5.3~rc2-1
4:7.5.4~rc1-1
4:7.5.4~rc1-2
4:7.5.4~rc1-3
4:7.5.4~rc1-4
4:7.5.4~rc2-1
4:7.5.4-1
4:7.5.4-2
4:7.5.4-3
4:7.5.4-4
4:7.5.5~rc1-1
4:7.5.5~rc1-2
4:7.5.5~rc1-3
4:7.5.5~rc1-4
4:7.5.5~rc1-5
4:7.5.5~rc2-1
4:7.5.5-1
4:7.5.5-2
4:7.5.5-3~bpo12+1
4:7.5.5-3
4:7.5.5-4~bpo12+1
4:7.5.5-4
4:7.5.6-1~bpo12+1
4:7.5.6-1
4:7.5.7-1
4:7.5.8~rc1-1
4:7.5.8~rc1-2
4:7.5.8-1~bpo12+1
4:7.5.8-1
4:7.5.9~rc1-1~bpo12+1
4:7.5.9~rc1-1~bpo12+2
4:7.5.9~rc1-1
4:7.6.0~rc1-1
4:7.6.0~rc1-2
4:7.6.0~rc2-1
4:7.6.0~rc2-2
4:7.6.0~rc3-1
4:7.6.1~rc1-1
4:7.6.1~rc2-1
4:7.6.1~rc2-2
4:7.6.2-1
4:7.6.2-2
4:7.6.2-3
4:7.6.2-4
4:7.6.2-5
4:7.6.3~rc1-1
4:7.6.3~rc1-2
4:7.6.3~rc2-1
4:7.6.3~rc2-2
4:7.6.3-1
4:7.6.3-2
4:7.6.4~rc1-1~bpo12+1
4:7.6.4~rc1-1

4:24.*

4:24.2.0~alpha1-1
4:24.2.0~beta1-1
4:24.2.0~rc1-1
4:24.2.0~rc1-2
4:24.2.0~rc2-1
4:24.2.0~rc2-2~bpo12+1
4:24.2.0~rc2-2
4:24.2.0-1~bpo12+1
4:24.2.0-1
4:24.2.0-2
4:24.2.0-3
4:24.2.1~rc1-1
4:24.2.1~rc2-1
4:24.2.1-1
4:24.2.1-2
4:24.2.1-3
4:24.2.1-4
4:24.2.2~rc1-1
4:24.2.2~rc1-2
4:24.2.2~rc2-1
4:24.2.2~rc2-2
4:24.2.2-1
4:24.2.2-2
4:24.2.2-3
4:24.2.3~rc1-1
4:24.2.3~rc1-2
4:24.2.3~rc1-3
4:24.2.3~rc2-1
4:24.2.3-1~bpo12+1
4:24.2.3-1
4:24.2.3-2
4:24.2.4-1~bpo12+1
4:24.2.4-1
4:24.2.5-1~bpo12+1
4:24.2.5-1
4:24.2.5-2
4:24.2.5-3
4:24.2.5-4
4:24.8.0~alpha1-1
4:24.8.0~alpha1-2
4:24.8.0~alpha1-3
4:24.8.0~alpha1-4
4:24.8.0~beta1-1
4:24.8.0~rc1-1
4:24.8.0~rc2-1
4:24.8.0~rc3-1
4:24.8.0~rc3-2
4:24.8.1~rc1-1

Ecosystem specific

{
    "urgency": "unimportant"
}

Debian:12 / libreoffice

Package

Name
libreoffice
Purl
pkg:deb/debian/libreoffice?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

4:7.*

4:7.4.5-3
4:7.4.7-1~bpo11+1
4:7.4.7-1
4:7.4.7-1+deb12u1~bpo11+1
4:7.4.7-1+deb12u1
4:7.4.7-1+deb12u2~bpo11+1
4:7.4.7-1+deb12u2
4:7.4.7-1+deb12u3
4:7.4.7-1+deb12u4
4:7.5.0~rc2-7
4:7.5.0~rc3-1
4:7.5.1~rc1-1
4:7.5.1~rc2-1
4:7.5.2~rc1-1
4:7.5.2~rc2-1
4:7.5.3~rc1-1
4:7.5.3~rc2-1
4:7.5.4~rc1-1
4:7.5.4~rc1-2
4:7.5.4~rc1-3
4:7.5.4~rc1-4
4:7.5.4~rc2-1
4:7.5.4-1
4:7.5.4-2
4:7.5.4-3
4:7.5.4-4
4:7.5.5~rc1-1
4:7.5.5~rc1-2
4:7.5.5~rc1-3
4:7.5.5~rc1-4
4:7.5.5~rc1-5
4:7.5.5~rc2-1
4:7.5.5-1
4:7.5.5-2
4:7.5.5-3~bpo12+1
4:7.5.5-3
4:7.5.5-4~bpo12+1
4:7.5.5-4
4:7.5.6-1~bpo12+1
4:7.5.6-1
4:7.5.7-1
4:7.5.8~rc1-1
4:7.5.8~rc1-2
4:7.5.8-1~bpo12+1
4:7.5.8-1
4:7.5.9~rc1-1~bpo12+1
4:7.5.9~rc1-1~bpo12+2
4:7.5.9~rc1-1
4:7.6.0~rc1-1
4:7.6.0~rc1-2
4:7.6.0~rc2-1
4:7.6.0~rc2-2
4:7.6.0~rc3-1
4:7.6.1~rc1-1
4:7.6.1~rc2-1
4:7.6.1~rc2-2
4:7.6.2-1
4:7.6.2-2
4:7.6.2-3
4:7.6.2-4
4:7.6.2-5
4:7.6.3~rc1-1
4:7.6.3~rc1-2
4:7.6.3~rc2-1
4:7.6.3~rc2-2
4:7.6.3-1
4:7.6.3-2
4:7.6.4~rc1-1~bpo12+1
4:7.6.4~rc1-1

4:24.*

4:24.2.0~alpha1-1
4:24.2.0~beta1-1
4:24.2.0~rc1-1
4:24.2.0~rc1-2
4:24.2.0~rc2-1
4:24.2.0~rc2-2~bpo12+1
4:24.2.0~rc2-2
4:24.2.0-1~bpo12+1
4:24.2.0-1
4:24.2.0-2
4:24.2.0-3
4:24.2.1~rc1-1
4:24.2.1~rc2-1
4:24.2.1-1
4:24.2.1-2
4:24.2.1-3
4:24.2.1-4
4:24.2.2~rc1-1
4:24.2.2~rc1-2
4:24.2.2~rc2-1
4:24.2.2~rc2-2
4:24.2.2-1
4:24.2.2-2
4:24.2.2-3
4:24.2.3~rc1-1
4:24.2.3~rc1-2
4:24.2.3~rc1-3
4:24.2.3~rc2-1
4:24.2.3-1~bpo12+1
4:24.2.3-1
4:24.2.3-2
4:24.2.4-1~bpo12+1
4:24.2.4-1
4:24.2.5-1~bpo12+1
4:24.2.5-1
4:24.2.5-2
4:24.2.5-3
4:24.2.5-4
4:24.8.0~alpha1-1
4:24.8.0~alpha1-2
4:24.8.0~alpha1-3
4:24.8.0~alpha1-4
4:24.8.0~beta1-1
4:24.8.0~rc1-1
4:24.8.0~rc2-1
4:24.8.0~rc3-1
4:24.8.0~rc3-2
4:24.8.1~rc1-1

Ecosystem specific

{
    "urgency": "unimportant"
}

Debian:13 / libreoffice

Package

Name
libreoffice
Purl
pkg:deb/debian/libreoffice?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

4:7.*

4:7.4.5-3
4:7.4.7-1~bpo11+1
4:7.4.7-1
4:7.5.0~rc2-7
4:7.5.0~rc3-1
4:7.5.1~rc1-1
4:7.5.1~rc2-1
4:7.5.2~rc1-1
4:7.5.2~rc2-1
4:7.5.3~rc1-1
4:7.5.3~rc2-1
4:7.5.4~rc1-1
4:7.5.4~rc1-2
4:7.5.4~rc1-3
4:7.5.4~rc1-4
4:7.5.4~rc2-1
4:7.5.4-1
4:7.5.4-2
4:7.5.4-3
4:7.5.4-4
4:7.5.5~rc1-1
4:7.5.5~rc1-2
4:7.5.5~rc1-3
4:7.5.5~rc1-4
4:7.5.5~rc1-5
4:7.5.5~rc2-1
4:7.5.5-1
4:7.5.5-2
4:7.5.5-3~bpo12+1
4:7.5.5-3
4:7.5.5-4~bpo12+1
4:7.5.5-4
4:7.5.6-1~bpo12+1
4:7.5.6-1
4:7.5.7-1
4:7.5.8~rc1-1
4:7.5.8~rc1-2
4:7.5.8-1~bpo12+1
4:7.5.8-1
4:7.5.9~rc1-1~bpo12+1
4:7.5.9~rc1-1~bpo12+2
4:7.5.9~rc1-1
4:7.6.0~rc1-1
4:7.6.0~rc1-2
4:7.6.0~rc2-1
4:7.6.0~rc2-2
4:7.6.0~rc3-1
4:7.6.1~rc1-1
4:7.6.1~rc2-1
4:7.6.1~rc2-2
4:7.6.2-1
4:7.6.2-2
4:7.6.2-3
4:7.6.2-4
4:7.6.2-5
4:7.6.3~rc1-1
4:7.6.3~rc1-2
4:7.6.3~rc2-1
4:7.6.3~rc2-2
4:7.6.3-1
4:7.6.3-2
4:7.6.4~rc1-1~bpo12+1
4:7.6.4~rc1-1

4:24.*

4:24.2.0~alpha1-1
4:24.2.0~beta1-1
4:24.2.0~rc1-1
4:24.2.0~rc1-2
4:24.2.0~rc2-1
4:24.2.0~rc2-2~bpo12+1
4:24.2.0~rc2-2
4:24.2.0-1~bpo12+1
4:24.2.0-1
4:24.2.0-2
4:24.2.0-3
4:24.2.1~rc1-1
4:24.2.1~rc2-1
4:24.2.1-1
4:24.2.1-2
4:24.2.1-3
4:24.2.1-4
4:24.2.2~rc1-1
4:24.2.2~rc1-2
4:24.2.2~rc2-1
4:24.2.2~rc2-2
4:24.2.2-1
4:24.2.2-2
4:24.2.2-3
4:24.2.3~rc1-1
4:24.2.3~rc1-2
4:24.2.3~rc1-3
4:24.2.3~rc2-1
4:24.2.3-1~bpo12+1
4:24.2.3-1
4:24.2.3-2
4:24.2.4-1~bpo12+1
4:24.2.4-1
4:24.2.5-1~bpo12+1
4:24.2.5-1
4:24.2.5-2
4:24.2.5-3
4:24.2.5-4
4:24.8.0~alpha1-1
4:24.8.0~alpha1-2
4:24.8.0~alpha1-3
4:24.8.0~alpha1-4
4:24.8.0~beta1-1
4:24.8.0~rc1-1
4:24.8.0~rc2-1
4:24.8.0~rc3-1
4:24.8.0~rc3-2
4:24.8.1~rc1-1

Ecosystem specific

{
    "urgency": "unimportant"
}

Git / github.com/libreoffice/core

Affected ranges

Type
GIT
Repo
https://github.com/libreoffice/core
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Last affected

Affected versions

Other

MELD_LIBREOFFICE_REPOS
libreoffice-3-5-branch-point
libreoffice-3-6-branch-point
libreoffice-4-0-branch-point
libreoffice-4-1-branch-point
libreoffice-4-2-branch-point
libreoffice-4-2-milestone-1
libreoffice-4-3-branch-point
libreoffice-4-4-branch-point
libreoffice-5-0-branch-point
libreoffice-5-1-branch-point
libreoffice-5-2-branch-point
libreoffice-5-3-branch-point
libreoffice-5-4-branch-point
libreoffice-6-0-branch-point
windows_build_successful_2011_11_08

calc_libreoffice-3.*

calc_libreoffice-3.4.2.2-buildfix1

cp-4.*

cp-4.1-1
cp-4.1-2
cp-4.1-3
cp-4.1-4
cp-4.1-5
cp-4.1-branch-point

cp-6.*

cp-6.0-1
cp-6.0-2
cp-6.0-3
cp-6.0-branch-point

gpg4libre-review-5.*

gpg4libre-review-5.4.99

libreoffice-3.*

libreoffice-3.5.0.0

libreoffice-4.*

libreoffice-4.1.0.1

libs-extern-sys_libreoffice-3.*

libs-extern-sys_libreoffice-3.4.2.2-buildfix1

libs-extern_libreoffice-3.*

libs-extern_libreoffice-3.4.2.2-buildfix1

sdremote-2.*

sdremote-2.0.0

testing_libreoffice-3.*

testing_libreoffice-3.3.99.4-hotfixes1