CVE-2018-6871

Impact:
Moderate
Public Date:
2018-02-12
CWE:
CWE-200
Bugzilla:
1543120: CVE-2018-6871 libreoffice: Remote arbitrary file disclosure vulnerability via WEBSERVICE formula
A flaw was found in libreoffice before 5.4.5 and before 6.0.1. Arbitrary remote file disclosure may be achieved by the use of the WEBSERVICE formula in a specially crafted ODS file.

Find out more about CVE-2018-6871 from the MITRE CVE dictionary dictionary and NIST NVD.

CVSS v3 metrics

CVSS3 Base Score 4.7
CVSS3 Base Metrics CVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N
Attack Vector Local
Attack Complexity High
Privileges Required None
User Interaction Required
Scope Unchanged
Confidentiality High
Integrity Impact None
Availability Impact None

Red Hat Security Errata

Platform Errata Release Date
Red Hat Enterprise Linux 6 (libreoffice) RHSA-2018:0517 2018-03-13
Red Hat Enterprise Linux 7 (libreoffice) RHSA-2018:0418 2018-03-06

External References

Last Modified
Close

Welcome! Check out the Getting Started with Red Hat page for quick tours and guides for common tasks.