LibreOffice CVE-2018-16858 Directory Traversal Vulnerability
BID:106837
Info
LibreOffice CVE-2018-16858 Directory Traversal Vulnerability
| Bugtraq ID: | 106837 |
| Class: | Design Error |
| CVE: |
CVE-2018-16858 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 01 2019 12:00AM |
| Updated: | Feb 01 2019 12:00AM |
| Credit: | Alex Inführ. |
| Vulnerable: |
Redhat Enterprise Linux 7 LibreOffice LibreOffice 6.1.2 LibreOffice LibreOffice 6.1 LibreOffice LibreOffice 6.0.6 LibreOffice LibreOffice 6.0.5 LibreOffice LibreOffice 6.0.4 LibreOffice LibreOffice 6.0.3 LibreOffice LibreOffice 6.0.2 LibreOffice LibreOffice 6.0.1 LibreOffice LibreOffice 6.1 |
| Not Vulnerable: |
LibreOffice LibreOffice 6.1.3 LibreOffice LibreOffice 6.0.7 |
Exploit / POC
LibreOffice CVE-2018-16858 Directory Traversal Vulnerability
The researcher has created a proof-of-concept to demonstrate the issue. Please see the references for more information.
The researcher has created a proof-of-concept to demonstrate the issue. Please see the references for more information.
Solution / Fix
LibreOffice CVE-2018-16858 Directory Traversal Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
LibreOffice CVE-2018-16858 Directory Traversal Vulnerability
References:
References:
- Libreoffice (CVE-2018-16858) - Remote Code Execution via Macro/Event execution (Blogspot)
- LibreOffice Home Page (LibreOffice)
- LibreOffice Product Page (LibreOffice)
- CVE-2018-16858 Directory traversal flaw in script execution (LibreOffice)
- CVE-2018-16858 libreoffice: Arbitrary python functions in arbitrary modules on t (Redhat)
- Red Hat Bugzilla �?? Bug 1649841 (Red Hat Bugzilla)