CVE-2018-10583: Apache Openoffice

High severity, CVSS 7.5. EPSS: 78% chance of exploitation in the next 30 days.

An information disclosure vulnerability occurs when LibreOffice 6.0.3 and Apache OpenOffice Writer 4.1.5 automatically process and initiate an SMB connection embedded in a malicious file, as demonstrated by xlink:href=file://192.168.0.2/test.jpg within an office:document-content element in a .odt XML document.

Affected products

  • Apache Openoffice: version 4.1.5 only
  • Canonical Ubuntu Linux: version 14.04 only; version 16.04 only
  • Debian Debian Linux: version 7.0 only; version 8.0 only; version 9.0 only
  • Libreoffice Libreoffice: version 6.0.3 only
  • Red Hat Enterprise Linux Desktop: version 7.0 only
  • Red Hat Enterprise Linux Server: version 7.0 only
  • Red Hat Enterprise Linux Workstation: version 7.0 only

Published 2018-05-01. Last modified 2026-06-17.