CVE-2018-10120
Published: 16 April 2018
The SwCTBWrapper::Read function in sw/source/filter/ww8/ww8toolbar.cxx in LibreOffice before 5.4.6.1 and 6.x before 6.0.2.1 does not validate a customizations index, which allows remote attackers to cause a denial of service (heap-based buffer overflow with write access) or possibly have unspecified other impact via a crafted document that contains a certain Microsoft Word record.
Priority
Status
Package | Release | Status |
---|---|---|
libreoffice Launchpad, Ubuntu, Debian |
upstream |
Needs triage
|
xenial |
Released
(1:5.1.6~rc2-0ubuntu1~xenial6)
|
|
artful |
Not vulnerable
(1:5.4.6-0ubuntu0.17.10.1)
|
|
bionic |
Not vulnerable
(1:6.0.3-0ubuntu1)
|
|
cosmic |
Not vulnerable
(1:6.0.3-0ubuntu1)
|
|
trusty |
Released
(1:4.2.8-0ubuntu5.5)
|
|
Patches: upstream: https://gerrit.libreoffice.org/gitweb?p=core.git;a=commit;h=017fcc2fcd00af17a97bd5463d89662404f57667 upstream: https://cgit.freedesktop.org/libreoffice/core/commit/?h=libreoffice-5-4&id=e355d7d691cfe9719b06e15129d86ec22a2bd7a4 (5.4) |
Severity score breakdown
Parameter | Value |
---|---|
Base score | 7.8 |
Attack vector | Local |
Attack complexity | Low |
Privileges required | None |
User interaction | Required |
Scope | Unchanged |
Confidentiality | High |
Integrity impact | High |
Availability impact | High |
Vector | CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
References
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-10120
- https://www.libreoffice.org/about-us/security/advisories/cve-2018-10120/
- https://gerrit.libreoffice.org/#/c/49486/
- https://gerrit.libreoffice.org/#/c/49499/
- https://gerrit.libreoffice.org/#/c/49500/
- https://ubuntu.com/security/notices/USN-3883-1
- NVD
- Launchpad
- Debian