CVE-2018-11790

Published: 31 December 2018

When loading a document with Apache Open Office 4.1.5 and earlier with smaller end line termination than the operating system uses, the defect occurs. In this case OpenOffice runs into an Arithmetic Overflow at a string length calculation.

Priority

Medium

CVSS 3 base score: 7.8

Status

Package Release Status
libreoffice
Launchpad, Ubuntu, Debian
Upstream
Released (1:5.0.3~rc1-1)
Ubuntu 18.04 LTS (Bionic Beaver) Not vulnerable
(1:6.0.7-0ubuntu0.18.04.2)
Ubuntu 16.04 ESM (Xenial Xerus) Not vulnerable
(1:5.1.6~rc2-0ubuntu1~xenial4)
Ubuntu 14.04 ESM (Trusty Tahr) Does not exist
(trusty was released [1:4.2.8-0ubuntu5.5])
Patches:
Upstream: https://github.com/LibreOffice/core/commit/ae850353151cd6a79f7b4a012d0a411013c841a4
Upstream: https://cgit.freedesktop.org/libreoffice/core/commit/?h=libreoffice-5-0&id=92eed31707e655e484e263fee2b0c0ae93d73748 (5.0)