CVE-2018-10583: Apache Openoffice
High severity, CVSS 7.5. EPSS: 78% chance of exploitation in the next 30 days.
An information disclosure vulnerability occurs when LibreOffice 6.0.3 and Apache OpenOffice Writer 4.1.5 automatically process and initiate an SMB connection embedded in a malicious file, as demonstrated by xlink:href=file://192.168.0.2/test.jpg within an office:document-content element in a .odt XML document.
Affected products
- Apache Openoffice: version 4.1.5 only
- Canonical Ubuntu Linux: version 14.04 only; version 16.04 only
- Debian Debian Linux: version 7.0 only; version 8.0 only; version 9.0 only
- Libreoffice Libreoffice: version 6.0.3 only
- Red Hat Enterprise Linux Desktop: version 7.0 only
- Red Hat Enterprise Linux Server: version 7.0 only
- Red Hat Enterprise Linux Workstation: version 7.0 only
Published 2018-05-01. Last modified 2026-06-17.