Language:
Severity: Critical
ID: 121640
File Name: ubuntu_USN-3883-1.nasl
Version: 1.15
Type: local
Agent: unix
Family: Ubuntu Local Security Checks
Published: 2/7/2019
Updated: 8/27/2024
Supported Sensors: Frictionless Assessment AWS, Frictionless Assessment Azure, Frictionless Assessment Agent, Nessus Agent, Agentless Assessment, Nessus
Risk Factor: Critical
Score: 9.5
Risk Factor: High
Base Score: 7.5
Temporal Score: 6.5
Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P
CVSS Score Source: CVE-2018-16858
Risk Factor: Critical
Base Score: 9.8
Temporal Score: 9.4
Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Temporal Vector: CVSS:3.0/E:H/RL:O/RC:C
CPE: p-cpe:/a:canonical:ubuntu_linux:libreoffice-style-human, p-cpe:/a:canonical:ubuntu_linux:libreoffice-l10n-za, p-cpe:/a:canonical:ubuntu_linux:libreoffice-style-hicontrast, p-cpe:/a:canonical:ubuntu_linux:libreoffice-calc, p-cpe:/a:canonical:ubuntu_linux:libreoffice-wiki-publisher, p-cpe:/a:canonical:ubuntu_linux:libreofficekit-dev, p-cpe:/a:canonical:ubuntu_linux:libreoffice-script-provider-js, p-cpe:/a:canonical:ubuntu_linux:libreoffice-sdbc-hsqldb, p-cpe:/a:canonical:ubuntu_linux:libreoffice-subsequentcheckbase, p-cpe:/a:canonical:ubuntu_linux:libreoffice-presentation-minimizer, p-cpe:/a:canonical:ubuntu_linux:libreoffice-script-provider-bsh, p-cpe:/a:canonical:ubuntu_linux:libreoffice-style-crystal, p-cpe:/a:canonical:ubuntu_linux:libreoffice, p-cpe:/a:canonical:ubuntu_linux:openoffice.org-dtd-officedocument1.0, p-cpe:/a:canonical:ubuntu_linux:libreoffice-style-tango, p-cpe:/a:canonical:ubuntu_linux:libreoffice-impress, p-cpe:/a:canonical:ubuntu_linux:libreoffice-style-galaxy, p-cpe:/a:canonical:ubuntu_linux:libreoffice-sdbc-firebird, p-cpe:/a:canonical:ubuntu_linux:python3-uno, p-cpe:/a:canonical:ubuntu_linux:libreoffice-script-provider-python, p-cpe:/a:canonical:ubuntu_linux:libreoffice-gtk3, p-cpe:/a:canonical:ubuntu_linux:browser-plugin-libreoffice, p-cpe:/a:canonical:ubuntu_linux:libreoffice-common, p-cpe:/a:canonical:ubuntu_linux:libreoffice-core, p-cpe:/a:canonical:ubuntu_linux:libreoffice-style-breeze, p-cpe:/a:canonical:ubuntu_linux:libreoffice-base-core, p-cpe:/a:canonical:ubuntu_linux:libreoffice-math, p-cpe:/a:canonical:ubuntu_linux:libreoffice-style-oxygen, cpe:/o:canonical:ubuntu_linux:14.04:-:lts, p-cpe:/a:canonical:ubuntu_linux:libreoffice-base, p-cpe:/a:canonical:ubuntu_linux:libreoffice-report-builder-bin, p-cpe:/a:canonical:ubuntu_linux:uno-libs3, p-cpe:/a:canonical:ubuntu_linux:libreoffice-ogltrans, p-cpe:/a:canonical:ubuntu_linux:libreoffice-avmedia-backend-gstreamer, p-cpe:/a:canonical:ubuntu_linux:libreoffice-l10n-in, p-cpe:/a:canonical:ubuntu_linux:libreoffice-sdbc-postgresql, p-cpe:/a:canonical:ubuntu_linux:libreoffice-dev, p-cpe:/a:canonical:ubuntu_linux:libreoffice-kde, p-cpe:/a:canonical:ubuntu_linux:libreoffice-style-sifr, p-cpe:/a:canonical:ubuntu_linux:libreoffice-mysql-connector, p-cpe:/a:canonical:ubuntu_linux:libreoffice-style-elementary, p-cpe:/a:canonical:ubuntu_linux:ure, p-cpe:/a:canonical:ubuntu_linux:libreoffice-librelogo, p-cpe:/a:canonical:ubuntu_linux:fonts-opensymbol, p-cpe:/a:canonical:ubuntu_linux:libreoffice-l10n-ku, p-cpe:/a:canonical:ubuntu_linux:libreoffice-gtk, cpe:/o:canonical:ubuntu_linux:16.04:-:lts, p-cpe:/a:canonical:ubuntu_linux:libreoffice-pdfimport, p-cpe:/a:canonical:ubuntu_linux:gir1.2-lokdocview-0.1, p-cpe:/a:canonical:ubuntu_linux:libreoffice-emailmerge, p-cpe:/a:canonical:ubuntu_linux:libreoffice-gnome, p-cpe:/a:canonical:ubuntu_linux:libreoffice-draw, p-cpe:/a:canonical:ubuntu_linux:libreoffice-java-common, p-cpe:/a:canonical:ubuntu_linux:libreoffice-writer, p-cpe:/a:canonical:ubuntu_linux:libreoffice-base-drivers, p-cpe:/a:canonical:ubuntu_linux:libreoffice-report-builder, p-cpe:/a:canonical:ubuntu_linux:libreoffice-officebean, p-cpe:/a:canonical:ubuntu_linux:libreoffice-presenter-console
Required KB Items: Host/cpu, Host/Debian/dpkg-l, Host/Ubuntu, Host/Ubuntu/release
Exploit Available: true
Exploit Ease: Exploits are available
Patch Publication Date: 2/6/2019
Vulnerability Publication Date: 4/16/2018
Metasploit (LibreOffice Macro Code Execution)
CVE: CVE-2018-10119, CVE-2018-10120, CVE-2018-10583, CVE-2018-11790, CVE-2018-16858
USN: 3883-1