ECHO-a8e4-9962-ca51

See a problem?
Import Source
https://advisory.echohq.com/osv/ECHO-a8e4-9962-ca51.json
JSON Data
https://api.osv.dev/v1/vulns/ECHO-a8e4-9962-ca51
Upstream
Withdrawn
2026-09-29T11:00:03Z
Published
2026-04-20T21:16:23Z
Modified
2026-09-29T11:45:37Z
Summary
Windows-only. The information disclosure is Windows automatically opening an SMB connection and sending the user's NTLM credentials when a document references file://<host>/<share> (e.g. xlink:href in an .odt). On Linux, LibreOffice does not reach SMB for such URLs and there is no automatic NTLM authentication, so nothing is disclosed. Upstream additionally restricted such accesses to trusted locations. Debian marks this issue unimportant ("generic behaviour of accessing remote SMB shares"). https://security-tracker.debian.org/tracker/CVE-2018-10583
Details
References

Affected packages

Echo / libreoffice

Package

Name
libreoffice
Purl
pkg:deb/echo/libreoffice

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
4:25.2.3-2+deb13u6

Database specific

source
"https://advisory.echohq.com/osv/ECHO-a8e4-9962-ca51.json"