USN-3883-1
Dashboard / Vulnerabilities / USN-3883-1
USN-3883-1
Summary: libreoffice vulnerabilities
Details: It was discovered that LibreOffice incorrectly handled certain document files. If a user were tricked into opening a specially crafted document, a remote attacker could cause LibreOffice to crash, and possibly execute arbitrary code. (CVE-2018-10119, CVE-2018-10120, CVE-2018-11790) It was discovered that LibreOffice incorrectly handled embedded SMB connections in document files. If a user were tricked in to opening a specially crafted document, a remote attacker could possibly exploit this to obtain sensitive information. (CVE-2018-10583) Alex Inführ discovered that LibreOffice incorrectly handled embedded scripts in document files. If a user were tricked into opening a specially crafted document, a remote attacker could possibly execute arbitrary code. (CVE-2018-16858)
References: https://ubuntu.com/security/notices/USN-3883-1, https://ubuntu.com/security/CVE-2018-10119, https://ubuntu.com/security/CVE-2018-10120, https://ubuntu.com/security/CVE-2018-10583, https://ubuntu.com/security/CVE-2018-11790, https://ubuntu.com/security/CVE-2018-16858
Affected packages
Package
Name: libreoffice
Purl: pkg:deb/ubuntu/libreoffice@1:4.2.8-0ubuntu5.5?arch=source&distro=trusty
Affected ranges
Type: ECOSYSTEM
Events:
