[Forgot Password]
Login  Register Subscribe

30430

 
 

423868

 
 

247768

 
 

909

 
 

194555

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

libreoffice: Arbitrary python functions in arbitrary modules on the filesystem can be executed without warning - CVE-2018-16858

Deprecated
ID: oval:org.secpod.oval:def:50618Date: (C)2019-02-07   (M)2023-12-20
Class: VULNERABILITYFamily: unix




It was found that libreoffice was vulnerable to a directory traversal attack which could be used to execute arbitrary macros bundled with a document. An attacker could craft a document, which when opened by LibreOffice, would execute a Python method from a script in any arbitrary file system location, specified relative to the LibreOffice install location.

Platform:
Red Hat Enterprise Linux 7
CentOS 7
Product:
LibreOffice
Reference:
CVE-2018-16858
CVE    1
CVE-2018-16858
CPE    3
cpe:/o:redhat:enterprise_linux:7
cpe:/a:libreoffice:libreoffice
cpe:/o:centos:centos:7

© SecPod Technologies