Vulnerabilities > CVE-2018-10119 - Use After Free vulnerability in multiple products
Attack vector
LOCAL Attack complexity
LOW Privileges required
NONE Confidentiality impact
HIGH Integrity impact
HIGH Availability impact
HIGH Summary
sot/source/sdstor/stgstrms.cxx in LibreOffice before 5.4.5.1 and 6.x before 6.0.1.1 uses an incorrect integer data type in the StgSmallStrm class, which allows remote attackers to cause a denial of service (use-after-free with write access) or possibly have unspecified other impact via a crafted document that uses the structured storage ole2 wrapper file format.
Vulnerable Configurations
Common Weakness Enumeration (CWE)
Nessus
NASL family Scientific Linux Local Security Checks NASL id SL_20181030_LIBREOFFICE_ON_SL7_X.NASL description Security Fix(es) : - libreoffice: Use-after-free in sdstor/stgstrms.cxx:StgSmallStrm class allows for denial of service with crafted document (CVE-2018-10119) - libreoffice: Out of bounds write in filter/ww8/ww8toolbar.cxx:SwCTBWrapper class allows for denial of service with crafted document (CVE-2018-10120) - libreoffice: Information disclosure via SMB connection embedded in malicious file (CVE-2018-10583) last seen 2020-03-18 modified 2018-11-27 plugin id 119192 published 2018-11-27 reporter This script is Copyright (C) 2018-2020 and is owned by Tenable, Inc. or an Affiliate thereof. source https://www.tenable.com/plugins/nessus/119192 title Scientific Linux Security Update : libreoffice on SL7.x x86_64 (20181030) code # # (C) Tenable Network Security, Inc. # # The descriptive text is (C) Scientific Linux. # include("compat.inc"); if (description) { script_id(119192); script_version("1.4"); script_set_attribute(attribute:"plugin_modification_date", value:"2020/02/24"); script_cve_id("CVE-2018-10119", "CVE-2018-10120", "CVE-2018-10583"); script_name(english:"Scientific Linux Security Update : libreoffice on SL7.x x86_64 (20181030)"); script_summary(english:"Checks rpm output for the updated packages"); script_set_attribute( attribute:"synopsis", value: "The remote Scientific Linux host is missing one or more security updates." ); script_set_attribute( attribute:"description", value: "Security Fix(es) : - libreoffice: Use-after-free in sdstor/stgstrms.cxx:StgSmallStrm class allows for denial of service with crafted document (CVE-2018-10119) - libreoffice: Out of bounds write in filter/ww8/ww8toolbar.cxx:SwCTBWrapper class allows for denial of service with crafted document (CVE-2018-10120) - libreoffice: Information disclosure via SMB connection embedded in malicious file (CVE-2018-10583)" ); # https://listserv.fnal.gov/scripts/wa.exe?A2=ind1811&L=scientific-linux-errata&F=&S=&P=6929 script_set_attribute( attribute:"see_also", value:"http://www.nessus.org/u?3493cda2" ); script_set_attribute(attribute:"solution", value:"Update the affected packages."); script_set_cvss_base_vector("CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P"); script_set_cvss_temporal_vector("CVSS2#E:POC/RL:OF/RC:C"); script_set_cvss3_base_vector("CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"); script_set_cvss3_temporal_vector("CVSS:3.0/E:P/RL:O/RC:C"); script_set_attribute(attribute:"exploitability_ease", value:"Exploits are available"); script_set_attribute(attribute:"exploit_available", value:"true"); script_set_attribute(attribute:"plugin_type", value:"local"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:fermilab:scientific_linux:autocorr-af"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:fermilab:scientific_linux:autocorr-bg"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:fermilab:scientific_linux:autocorr-ca"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:fermilab:scientific_linux:autocorr-cs"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:fermilab:scientific_linux:autocorr-da"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:fermilab:scientific_linux:autocorr-de"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:fermilab:scientific_linux:autocorr-en"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:fermilab:scientific_linux:autocorr-es"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:fermilab:scientific_linux:autocorr-fa"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:fermilab:scientific_linux:autocorr-fi"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:fermilab:scientific_linux:autocorr-fr"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:fermilab:scientific_linux:autocorr-ga"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:fermilab:scientific_linux:autocorr-hr"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:fermilab:scientific_linux:autocorr-hu"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:fermilab:scientific_linux:autocorr-is"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:fermilab:scientific_linux:autocorr-it"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:fermilab:scientific_linux:autocorr-ja"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:fermilab:scientific_linux:autocorr-ko"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:fermilab:scientific_linux:autocorr-lb"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:fermilab:scientific_linux:autocorr-lt"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:fermilab:scientific_linux:autocorr-mn"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:fermilab:scientific_linux:autocorr-nl"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:fermilab:scientific_linux:autocorr-pl"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:fermilab:scientific_linux:autocorr-pt"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:fermilab:scientific_linux:autocorr-ro"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:fermilab:scientific_linux:autocorr-ru"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:fermilab:scientific_linux:autocorr-sk"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:fermilab:scientific_linux:autocorr-sl"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:fermilab:scientific_linux:autocorr-sr"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:fermilab:scientific_linux:autocorr-sv"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:fermilab:scientific_linux:autocorr-tr"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:fermilab:scientific_linux:autocorr-vi"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:fermilab:scientific_linux:autocorr-zh"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:fermilab:scientific_linux:libreoffice"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:fermilab:scientific_linux:libreoffice-base"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:fermilab:scientific_linux:libreoffice-bsh"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:fermilab:scientific_linux:libreoffice-calc"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:fermilab:scientific_linux:libreoffice-core"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:fermilab:scientific_linux:libreoffice-data"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:fermilab:scientific_linux:libreoffice-debuginfo"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:fermilab:scientific_linux:libreoffice-draw"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:fermilab:scientific_linux:libreoffice-emailmerge"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:fermilab:scientific_linux:libreoffice-filters"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:fermilab:scientific_linux:libreoffice-gdb-debug-support"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:fermilab:scientific_linux:libreoffice-glade"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:fermilab:scientific_linux:libreoffice-graphicfilter"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:fermilab:scientific_linux:libreoffice-gtk2"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:fermilab:scientific_linux:libreoffice-gtk3"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:fermilab:scientific_linux:libreoffice-help-ar"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:fermilab:scientific_linux:libreoffice-help-bg"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:fermilab:scientific_linux:libreoffice-help-bn"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:fermilab:scientific_linux:libreoffice-help-ca"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:fermilab:scientific_linux:libreoffice-help-cs"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:fermilab:scientific_linux:libreoffice-help-da"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:fermilab:scientific_linux:libreoffice-help-de"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:fermilab:scientific_linux:libreoffice-help-dz"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:fermilab:scientific_linux:libreoffice-help-el"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:fermilab:scientific_linux:libreoffice-help-es"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:fermilab:scientific_linux:libreoffice-help-et"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:fermilab:scientific_linux:libreoffice-help-eu"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:fermilab:scientific_linux:libreoffice-help-fi"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:fermilab:scientific_linux:libreoffice-help-fr"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:fermilab:scientific_linux:libreoffice-help-gl"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:fermilab:scientific_linux:libreoffice-help-gu"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:fermilab:scientific_linux:libreoffice-help-he"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:fermilab:scientific_linux:libreoffice-help-hi"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:fermilab:scientific_linux:libreoffice-help-hr"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:fermilab:scientific_linux:libreoffice-help-hu"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:fermilab:scientific_linux:libreoffice-help-id"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:fermilab:scientific_linux:libreoffice-help-it"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:fermilab:scientific_linux:libreoffice-help-ja"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:fermilab:scientific_linux:libreoffice-help-ko"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:fermilab:scientific_linux:libreoffice-help-lt"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:fermilab:scientific_linux:libreoffice-help-lv"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:fermilab:scientific_linux:libreoffice-help-nb"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:fermilab:scientific_linux:libreoffice-help-nl"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:fermilab:scientific_linux:libreoffice-help-nn"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:fermilab:scientific_linux:libreoffice-help-pl"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:fermilab:scientific_linux:libreoffice-help-pt-BR"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:fermilab:scientific_linux:libreoffice-help-pt-PT"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:fermilab:scientific_linux:libreoffice-help-ro"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:fermilab:scientific_linux:libreoffice-help-ru"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:fermilab:scientific_linux:libreoffice-help-si"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:fermilab:scientific_linux:libreoffice-help-sk"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:fermilab:scientific_linux:libreoffice-help-sl"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:fermilab:scientific_linux:libreoffice-help-sv"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:fermilab:scientific_linux:libreoffice-help-ta"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:fermilab:scientific_linux:libreoffice-help-tr"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:fermilab:scientific_linux:libreoffice-help-uk"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:fermilab:scientific_linux:libreoffice-help-zh-Hans"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:fermilab:scientific_linux:libreoffice-help-zh-Hant"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:fermilab:scientific_linux:libreoffice-impress"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:fermilab:scientific_linux:libreoffice-langpack-af"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:fermilab:scientific_linux:libreoffice-langpack-ar"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:fermilab:scientific_linux:libreoffice-langpack-as"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:fermilab:scientific_linux:libreoffice-langpack-bg"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:fermilab:scientific_linux:libreoffice-langpack-bn"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:fermilab:scientific_linux:libreoffice-langpack-br"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:fermilab:scientific_linux:libreoffice-langpack-ca"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:fermilab:scientific_linux:libreoffice-langpack-cs"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:fermilab:scientific_linux:libreoffice-langpack-cy"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:fermilab:scientific_linux:libreoffice-langpack-da"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:fermilab:scientific_linux:libreoffice-langpack-de"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:fermilab:scientific_linux:libreoffice-langpack-dz"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:fermilab:scientific_linux:libreoffice-langpack-el"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:fermilab:scientific_linux:libreoffice-langpack-en"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:fermilab:scientific_linux:libreoffice-langpack-es"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:fermilab:scientific_linux:libreoffice-langpack-et"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:fermilab:scientific_linux:libreoffice-langpack-eu"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:fermilab:scientific_linux:libreoffice-langpack-fa"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:fermilab:scientific_linux:libreoffice-langpack-fi"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:fermilab:scientific_linux:libreoffice-langpack-fr"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:fermilab:scientific_linux:libreoffice-langpack-ga"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:fermilab:scientific_linux:libreoffice-langpack-gl"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:fermilab:scientific_linux:libreoffice-langpack-gu"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:fermilab:scientific_linux:libreoffice-langpack-he"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:fermilab:scientific_linux:libreoffice-langpack-hi"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:fermilab:scientific_linux:libreoffice-langpack-hr"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:fermilab:scientific_linux:libreoffice-langpack-hu"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:fermilab:scientific_linux:libreoffice-langpack-id"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:fermilab:scientific_linux:libreoffice-langpack-it"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:fermilab:scientific_linux:libreoffice-langpack-ja"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:fermilab:scientific_linux:libreoffice-langpack-kk"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:fermilab:scientific_linux:libreoffice-langpack-kn"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:fermilab:scientific_linux:libreoffice-langpack-ko"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:fermilab:scientific_linux:libreoffice-langpack-lt"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:fermilab:scientific_linux:libreoffice-langpack-lv"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:fermilab:scientific_linux:libreoffice-langpack-mai"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:fermilab:scientific_linux:libreoffice-langpack-ml"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:fermilab:scientific_linux:libreoffice-langpack-mr"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:fermilab:scientific_linux:libreoffice-langpack-nb"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:fermilab:scientific_linux:libreoffice-langpack-nl"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:fermilab:scientific_linux:libreoffice-langpack-nn"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:fermilab:scientific_linux:libreoffice-langpack-nr"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:fermilab:scientific_linux:libreoffice-langpack-nso"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:fermilab:scientific_linux:libreoffice-langpack-or"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:fermilab:scientific_linux:libreoffice-langpack-pa"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:fermilab:scientific_linux:libreoffice-langpack-pl"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:fermilab:scientific_linux:libreoffice-langpack-pt-BR"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:fermilab:scientific_linux:libreoffice-langpack-pt-PT"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:fermilab:scientific_linux:libreoffice-langpack-ro"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:fermilab:scientific_linux:libreoffice-langpack-ru"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:fermilab:scientific_linux:libreoffice-langpack-si"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:fermilab:scientific_linux:libreoffice-langpack-sk"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:fermilab:scientific_linux:libreoffice-langpack-sl"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:fermilab:scientific_linux:libreoffice-langpack-sr"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:fermilab:scientific_linux:libreoffice-langpack-ss"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:fermilab:scientific_linux:libreoffice-langpack-st"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:fermilab:scientific_linux:libreoffice-langpack-sv"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:fermilab:scientific_linux:libreoffice-langpack-ta"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:fermilab:scientific_linux:libreoffice-langpack-te"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:fermilab:scientific_linux:libreoffice-langpack-th"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:fermilab:scientific_linux:libreoffice-langpack-tn"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:fermilab:scientific_linux:libreoffice-langpack-tr"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:fermilab:scientific_linux:libreoffice-langpack-ts"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:fermilab:scientific_linux:libreoffice-langpack-uk"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:fermilab:scientific_linux:libreoffice-langpack-ve"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:fermilab:scientific_linux:libreoffice-langpack-xh"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:fermilab:scientific_linux:libreoffice-langpack-zh-Hans"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:fermilab:scientific_linux:libreoffice-langpack-zh-Hant"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:fermilab:scientific_linux:libreoffice-langpack-zu"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:fermilab:scientific_linux:libreoffice-librelogo"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:fermilab:scientific_linux:libreoffice-math"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:fermilab:scientific_linux:libreoffice-nlpsolver"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:fermilab:scientific_linux:libreoffice-officebean"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:fermilab:scientific_linux:libreoffice-officebean-common"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:fermilab:scientific_linux:libreoffice-ogltrans"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:fermilab:scientific_linux:libreoffice-opensymbol-fonts"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:fermilab:scientific_linux:libreoffice-pdfimport"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:fermilab:scientific_linux:libreoffice-postgresql"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:fermilab:scientific_linux:libreoffice-pyuno"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:fermilab:scientific_linux:libreoffice-rhino"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:fermilab:scientific_linux:libreoffice-sdk"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:fermilab:scientific_linux:libreoffice-sdk-doc"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:fermilab:scientific_linux:libreoffice-ure"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:fermilab:scientific_linux:libreoffice-ure-common"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:fermilab:scientific_linux:libreoffice-wiki-publisher"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:fermilab:scientific_linux:libreoffice-writer"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:fermilab:scientific_linux:libreoffice-x11"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:fermilab:scientific_linux:libreoffice-xsltfilter"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:fermilab:scientific_linux:libreofficekit"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:fermilab:scientific_linux:libreofficekit-devel"); script_set_attribute(attribute:"cpe", value:"x-cpe:/o:fermilab:scientific_linux"); script_set_attribute(attribute:"vuln_publication_date", value:"2018/04/16"); script_set_attribute(attribute:"patch_publication_date", value:"2018/10/30"); script_set_attribute(attribute:"plugin_publication_date", value:"2018/11/27"); script_set_attribute(attribute:"generated_plugin", value:"current"); script_end_attributes(); script_category(ACT_GATHER_INFO); script_copyright(english:"This script is Copyright (C) 2018-2020 and is owned by Tenable, Inc. or an Affiliate thereof."); script_family(english:"Scientific Linux Local Security Checks"); script_dependencies("ssh_get_info.nasl"); script_require_keys("Host/local_checks_enabled", "Host/cpu", "Host/RedHat/release", "Host/RedHat/rpm-list"); exit(0); } include("audit.inc"); include("global_settings.inc"); include("misc_func.inc"); include("rpm.inc"); if (!get_kb_item("Host/local_checks_enabled")) audit(AUDIT_LOCAL_CHECKS_NOT_ENABLED); release = get_kb_item("Host/RedHat/release"); if (isnull(release) || "Scientific Linux " >!< release) audit(AUDIT_HOST_NOT, "running Scientific Linux"); os_ver = pregmatch(pattern: "Scientific Linux.*release ([0-9]+(\.[0-9]+)?)", string:release); if (isnull(os_ver)) audit(AUDIT_UNKNOWN_APP_VER, "Scientific Linux"); os_ver = os_ver[1]; if (! preg(pattern:"^7([^0-9]|$)", string:os_ver)) audit(AUDIT_OS_NOT, "Scientific Linux 7.x", "Scientific Linux " + os_ver); if (!get_kb_item("Host/RedHat/rpm-list")) audit(AUDIT_PACKAGE_LIST_MISSING); cpu = get_kb_item("Host/cpu"); if (isnull(cpu)) audit(AUDIT_UNKNOWN_ARCH); if (cpu >!< "x86_64" && cpu !~ "^i[3-6]86$") audit(AUDIT_LOCAL_CHECKS_NOT_IMPLEMENTED, "Scientific Linux", cpu); flag = 0; if (rpm_check(release:"SL7", reference:"autocorr-af-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"SL7", reference:"autocorr-bg-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"SL7", reference:"autocorr-ca-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"SL7", reference:"autocorr-cs-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"SL7", reference:"autocorr-da-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"SL7", reference:"autocorr-de-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"SL7", reference:"autocorr-en-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"SL7", reference:"autocorr-es-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"SL7", reference:"autocorr-fa-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"SL7", reference:"autocorr-fi-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"SL7", reference:"autocorr-fr-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"SL7", reference:"autocorr-ga-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"SL7", reference:"autocorr-hr-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"SL7", reference:"autocorr-hu-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"SL7", reference:"autocorr-is-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"SL7", reference:"autocorr-it-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"SL7", reference:"autocorr-ja-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"SL7", reference:"autocorr-ko-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"SL7", reference:"autocorr-lb-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"SL7", reference:"autocorr-lt-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"SL7", reference:"autocorr-mn-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"SL7", reference:"autocorr-nl-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"SL7", reference:"autocorr-pl-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"SL7", reference:"autocorr-pt-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"SL7", reference:"autocorr-ro-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"SL7", reference:"autocorr-ru-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"SL7", reference:"autocorr-sk-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"SL7", reference:"autocorr-sl-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"SL7", reference:"autocorr-sr-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"SL7", reference:"autocorr-sv-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"SL7", reference:"autocorr-tr-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"SL7", reference:"autocorr-vi-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"SL7", reference:"autocorr-zh-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"SL7", cpu:"x86_64", reference:"libreoffice-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"SL7", cpu:"x86_64", reference:"libreoffice-base-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"SL7", cpu:"x86_64", reference:"libreoffice-bsh-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"SL7", cpu:"x86_64", reference:"libreoffice-calc-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"SL7", cpu:"x86_64", reference:"libreoffice-core-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"SL7", reference:"libreoffice-data-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"SL7", cpu:"x86_64", reference:"libreoffice-debuginfo-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"SL7", cpu:"x86_64", reference:"libreoffice-draw-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"SL7", cpu:"x86_64", reference:"libreoffice-emailmerge-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"SL7", cpu:"x86_64", reference:"libreoffice-filters-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"SL7", cpu:"x86_64", reference:"libreoffice-gdb-debug-support-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"SL7", cpu:"x86_64", reference:"libreoffice-glade-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"SL7", cpu:"x86_64", reference:"libreoffice-graphicfilter-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"SL7", cpu:"x86_64", reference:"libreoffice-gtk2-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"SL7", cpu:"x86_64", reference:"libreoffice-gtk3-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"SL7", cpu:"x86_64", reference:"libreoffice-help-ar-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"SL7", cpu:"x86_64", reference:"libreoffice-help-bg-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"SL7", cpu:"x86_64", reference:"libreoffice-help-bn-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"SL7", cpu:"x86_64", reference:"libreoffice-help-ca-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"SL7", cpu:"x86_64", reference:"libreoffice-help-cs-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"SL7", cpu:"x86_64", reference:"libreoffice-help-da-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"SL7", cpu:"x86_64", reference:"libreoffice-help-de-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"SL7", cpu:"x86_64", reference:"libreoffice-help-dz-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"SL7", cpu:"x86_64", reference:"libreoffice-help-el-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"SL7", cpu:"x86_64", reference:"libreoffice-help-es-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"SL7", cpu:"x86_64", reference:"libreoffice-help-et-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"SL7", cpu:"x86_64", reference:"libreoffice-help-eu-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"SL7", cpu:"x86_64", reference:"libreoffice-help-fi-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"SL7", cpu:"x86_64", reference:"libreoffice-help-fr-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"SL7", cpu:"x86_64", reference:"libreoffice-help-gl-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"SL7", cpu:"x86_64", reference:"libreoffice-help-gu-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"SL7", cpu:"x86_64", reference:"libreoffice-help-he-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"SL7", cpu:"x86_64", reference:"libreoffice-help-hi-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"SL7", cpu:"x86_64", reference:"libreoffice-help-hr-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"SL7", cpu:"x86_64", reference:"libreoffice-help-hu-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"SL7", cpu:"x86_64", reference:"libreoffice-help-id-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"SL7", cpu:"x86_64", reference:"libreoffice-help-it-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"SL7", cpu:"x86_64", reference:"libreoffice-help-ja-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"SL7", cpu:"x86_64", reference:"libreoffice-help-ko-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"SL7", cpu:"x86_64", reference:"libreoffice-help-lt-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"SL7", cpu:"x86_64", reference:"libreoffice-help-lv-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"SL7", cpu:"x86_64", reference:"libreoffice-help-nb-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"SL7", cpu:"x86_64", reference:"libreoffice-help-nl-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"SL7", cpu:"x86_64", reference:"libreoffice-help-nn-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"SL7", cpu:"x86_64", reference:"libreoffice-help-pl-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"SL7", cpu:"x86_64", reference:"libreoffice-help-pt-BR-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"SL7", cpu:"x86_64", reference:"libreoffice-help-pt-PT-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"SL7", cpu:"x86_64", reference:"libreoffice-help-ro-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"SL7", cpu:"x86_64", reference:"libreoffice-help-ru-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"SL7", cpu:"x86_64", reference:"libreoffice-help-si-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"SL7", cpu:"x86_64", reference:"libreoffice-help-sk-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"SL7", cpu:"x86_64", reference:"libreoffice-help-sl-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"SL7", cpu:"x86_64", reference:"libreoffice-help-sv-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"SL7", cpu:"x86_64", reference:"libreoffice-help-ta-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"SL7", cpu:"x86_64", reference:"libreoffice-help-tr-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"SL7", cpu:"x86_64", reference:"libreoffice-help-uk-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"SL7", cpu:"x86_64", reference:"libreoffice-help-zh-Hans-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"SL7", cpu:"x86_64", reference:"libreoffice-help-zh-Hant-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"SL7", cpu:"x86_64", reference:"libreoffice-impress-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"SL7", cpu:"x86_64", reference:"libreoffice-langpack-af-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"SL7", cpu:"x86_64", reference:"libreoffice-langpack-ar-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"SL7", cpu:"x86_64", reference:"libreoffice-langpack-as-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"SL7", cpu:"x86_64", reference:"libreoffice-langpack-bg-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"SL7", cpu:"x86_64", reference:"libreoffice-langpack-bn-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"SL7", cpu:"x86_64", reference:"libreoffice-langpack-br-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"SL7", cpu:"x86_64", reference:"libreoffice-langpack-ca-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"SL7", cpu:"x86_64", reference:"libreoffice-langpack-cs-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"SL7", cpu:"x86_64", reference:"libreoffice-langpack-cy-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"SL7", cpu:"x86_64", reference:"libreoffice-langpack-da-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"SL7", cpu:"x86_64", reference:"libreoffice-langpack-de-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"SL7", cpu:"x86_64", reference:"libreoffice-langpack-dz-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"SL7", cpu:"x86_64", reference:"libreoffice-langpack-el-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"SL7", cpu:"x86_64", reference:"libreoffice-langpack-en-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"SL7", cpu:"x86_64", reference:"libreoffice-langpack-es-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"SL7", cpu:"x86_64", reference:"libreoffice-langpack-et-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"SL7", cpu:"x86_64", reference:"libreoffice-langpack-eu-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"SL7", cpu:"x86_64", reference:"libreoffice-langpack-fa-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"SL7", cpu:"x86_64", reference:"libreoffice-langpack-fi-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"SL7", cpu:"x86_64", reference:"libreoffice-langpack-fr-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"SL7", cpu:"x86_64", reference:"libreoffice-langpack-ga-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"SL7", cpu:"x86_64", reference:"libreoffice-langpack-gl-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"SL7", cpu:"x86_64", reference:"libreoffice-langpack-gu-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"SL7", cpu:"x86_64", reference:"libreoffice-langpack-he-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"SL7", cpu:"x86_64", reference:"libreoffice-langpack-hi-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"SL7", cpu:"x86_64", reference:"libreoffice-langpack-hr-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"SL7", cpu:"x86_64", reference:"libreoffice-langpack-hu-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"SL7", cpu:"x86_64", reference:"libreoffice-langpack-id-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"SL7", cpu:"x86_64", reference:"libreoffice-langpack-it-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"SL7", cpu:"x86_64", reference:"libreoffice-langpack-ja-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"SL7", cpu:"x86_64", reference:"libreoffice-langpack-kk-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"SL7", cpu:"x86_64", reference:"libreoffice-langpack-kn-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"SL7", cpu:"x86_64", reference:"libreoffice-langpack-ko-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"SL7", cpu:"x86_64", reference:"libreoffice-langpack-lt-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"SL7", cpu:"x86_64", reference:"libreoffice-langpack-lv-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"SL7", cpu:"x86_64", reference:"libreoffice-langpack-mai-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"SL7", cpu:"x86_64", reference:"libreoffice-langpack-ml-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"SL7", cpu:"x86_64", reference:"libreoffice-langpack-mr-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"SL7", cpu:"x86_64", reference:"libreoffice-langpack-nb-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"SL7", cpu:"x86_64", reference:"libreoffice-langpack-nl-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"SL7", cpu:"x86_64", reference:"libreoffice-langpack-nn-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"SL7", cpu:"x86_64", reference:"libreoffice-langpack-nr-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"SL7", cpu:"x86_64", reference:"libreoffice-langpack-nso-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"SL7", cpu:"x86_64", reference:"libreoffice-langpack-or-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"SL7", cpu:"x86_64", reference:"libreoffice-langpack-pa-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"SL7", cpu:"x86_64", reference:"libreoffice-langpack-pl-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"SL7", cpu:"x86_64", reference:"libreoffice-langpack-pt-BR-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"SL7", cpu:"x86_64", reference:"libreoffice-langpack-pt-PT-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"SL7", cpu:"x86_64", reference:"libreoffice-langpack-ro-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"SL7", cpu:"x86_64", reference:"libreoffice-langpack-ru-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"SL7", cpu:"x86_64", reference:"libreoffice-langpack-si-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"SL7", cpu:"x86_64", reference:"libreoffice-langpack-sk-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"SL7", cpu:"x86_64", reference:"libreoffice-langpack-sl-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"SL7", cpu:"x86_64", reference:"libreoffice-langpack-sr-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"SL7", cpu:"x86_64", reference:"libreoffice-langpack-ss-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"SL7", cpu:"x86_64", reference:"libreoffice-langpack-st-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"SL7", cpu:"x86_64", reference:"libreoffice-langpack-sv-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"SL7", cpu:"x86_64", reference:"libreoffice-langpack-ta-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"SL7", cpu:"x86_64", reference:"libreoffice-langpack-te-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"SL7", cpu:"x86_64", reference:"libreoffice-langpack-th-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"SL7", cpu:"x86_64", reference:"libreoffice-langpack-tn-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"SL7", cpu:"x86_64", reference:"libreoffice-langpack-tr-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"SL7", cpu:"x86_64", reference:"libreoffice-langpack-ts-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"SL7", cpu:"x86_64", reference:"libreoffice-langpack-uk-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"SL7", cpu:"x86_64", reference:"libreoffice-langpack-ve-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"SL7", cpu:"x86_64", reference:"libreoffice-langpack-xh-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"SL7", cpu:"x86_64", reference:"libreoffice-langpack-zh-Hans-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"SL7", cpu:"x86_64", reference:"libreoffice-langpack-zh-Hant-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"SL7", cpu:"x86_64", reference:"libreoffice-langpack-zu-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"SL7", cpu:"x86_64", reference:"libreoffice-librelogo-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"SL7", cpu:"x86_64", reference:"libreoffice-math-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"SL7", cpu:"x86_64", reference:"libreoffice-nlpsolver-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"SL7", cpu:"x86_64", reference:"libreoffice-officebean-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"SL7", reference:"libreoffice-officebean-common-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"SL7", cpu:"x86_64", reference:"libreoffice-ogltrans-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"SL7", reference:"libreoffice-opensymbol-fonts-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"SL7", cpu:"x86_64", reference:"libreoffice-pdfimport-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"SL7", cpu:"x86_64", reference:"libreoffice-postgresql-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"SL7", cpu:"x86_64", reference:"libreoffice-pyuno-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"SL7", cpu:"x86_64", reference:"libreoffice-rhino-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"SL7", cpu:"x86_64", reference:"libreoffice-sdk-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"SL7", cpu:"x86_64", reference:"libreoffice-sdk-doc-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"SL7", cpu:"x86_64", reference:"libreoffice-ure-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"SL7", reference:"libreoffice-ure-common-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"SL7", cpu:"x86_64", reference:"libreoffice-wiki-publisher-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"SL7", cpu:"x86_64", reference:"libreoffice-writer-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"SL7", cpu:"x86_64", reference:"libreoffice-x11-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"SL7", cpu:"x86_64", reference:"libreoffice-xsltfilter-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"SL7", cpu:"x86_64", reference:"libreofficekit-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"SL7", cpu:"x86_64", reference:"libreofficekit-devel-5.3.6.1-19.el7")) flag++; if (flag) { security_report_v4( port : 0, severity : SECURITY_WARNING, extra : rpm_report_get() ); exit(0); } else { tested = pkg_tests_get(); if (tested) audit(AUDIT_PACKAGE_NOT_AFFECTED, tested); else audit(AUDIT_PACKAGE_NOT_INSTALLED, "autocorr-af / autocorr-bg / autocorr-ca / autocorr-cs / autocorr-da / etc"); }
NASL family Red Hat Local Security Checks NASL id REDHAT-RHSA-2018-3054.NASL description An update for libreoffice is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. LibreOffice is an open source, community-developed office productivity suite. It includes key desktop applications, such as a word processor, a spreadsheet, a presentation manager, a formula editor, and a drawing program. LibreOffice replaces OpenOffice and provides a similar but enhanced and extended office suite. Security Fix(es) : * libreoffice: Use-after-free in sdstor/stgstrms.cxx:StgSmallStrm class allows for denial of service with crafted document (CVE-2018-10119) * libreoffice: Out of bounds write in filter/ww8/ww8toolbar.cxx:SwCTBWrapper class allows for denial of service with crafted document (CVE-2018-10120) * libreoffice: Information disclosure via SMB connection embedded in malicious file (CVE-2018-10583) For more details about the security issue(s), including the impact, a CVSS score, and other related information, refer to the CVE page(s) listed in the References section. Additional Changes : For detailed information on changes in this release, see the Red Hat Enterprise Linux 7.6 Release Notes linked from the References section. last seen 2020-06-01 modified 2020-06-02 plugin id 118518 published 2018-10-31 reporter This script is Copyright (C) 2018-2019 and is owned by Tenable, Inc. or an Affiliate thereof. source https://www.tenable.com/plugins/nessus/118518 title RHEL 7 : libreoffice (RHSA-2018:3054) code # # (C) Tenable Network Security, Inc. # # The descriptive text and package checks in this plugin were # extracted from Red Hat Security Advisory RHSA-2018:3054. The text # itself is copyright (C) Red Hat, Inc. # include("compat.inc"); if (description) { script_id(118518); script_version("1.6"); script_cvs_date("Date: 2019/10/24 15:35:45"); script_cve_id("CVE-2018-10119", "CVE-2018-10120", "CVE-2018-10583"); script_xref(name:"RHSA", value:"2018:3054"); script_name(english:"RHEL 7 : libreoffice (RHSA-2018:3054)"); script_summary(english:"Checks the rpm output for the updated packages"); script_set_attribute( attribute:"synopsis", value:"The remote Red Hat host is missing one or more security updates." ); script_set_attribute( attribute:"description", value: "An update for libreoffice is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. LibreOffice is an open source, community-developed office productivity suite. It includes key desktop applications, such as a word processor, a spreadsheet, a presentation manager, a formula editor, and a drawing program. LibreOffice replaces OpenOffice and provides a similar but enhanced and extended office suite. Security Fix(es) : * libreoffice: Use-after-free in sdstor/stgstrms.cxx:StgSmallStrm class allows for denial of service with crafted document (CVE-2018-10119) * libreoffice: Out of bounds write in filter/ww8/ww8toolbar.cxx:SwCTBWrapper class allows for denial of service with crafted document (CVE-2018-10120) * libreoffice: Information disclosure via SMB connection embedded in malicious file (CVE-2018-10583) For more details about the security issue(s), including the impact, a CVSS score, and other related information, refer to the CVE page(s) listed in the References section. Additional Changes : For detailed information on changes in this release, see the Red Hat Enterprise Linux 7.6 Release Notes linked from the References section." ); # https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/7/ script_set_attribute( attribute:"see_also", value:"http://www.nessus.org/u?3395ff0b" ); script_set_attribute( attribute:"see_also", value:"https://access.redhat.com/errata/RHSA-2018:3054" ); script_set_attribute( attribute:"see_also", value:"https://access.redhat.com/security/cve/cve-2018-10119" ); script_set_attribute( attribute:"see_also", value:"https://access.redhat.com/security/cve/cve-2018-10120" ); script_set_attribute( attribute:"see_also", value:"https://access.redhat.com/security/cve/cve-2018-10583" ); script_set_attribute(attribute:"solution", value:"Update the affected packages."); script_set_cvss_base_vector("CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P"); script_set_cvss_temporal_vector("CVSS2#E:POC/RL:OF/RC:C"); script_set_cvss3_base_vector("CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"); script_set_cvss3_temporal_vector("CVSS:3.0/E:P/RL:O/RC:C"); script_set_attribute(attribute:"exploitability_ease", value:"Exploits are available"); script_set_attribute(attribute:"exploit_available", value:"true"); script_set_attribute(attribute:"plugin_type", value:"local"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:autocorr-af"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:autocorr-bg"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:autocorr-ca"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:autocorr-cs"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:autocorr-da"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:autocorr-de"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:autocorr-en"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:autocorr-es"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:autocorr-fa"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:autocorr-fi"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:autocorr-fr"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:autocorr-ga"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:autocorr-hr"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:autocorr-hu"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:autocorr-is"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:autocorr-it"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:autocorr-ja"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:autocorr-ko"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:autocorr-lb"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:autocorr-lt"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:autocorr-mn"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:autocorr-nl"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:autocorr-pl"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:autocorr-pt"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:autocorr-ro"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:autocorr-ru"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:autocorr-sk"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:autocorr-sl"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:autocorr-sr"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:autocorr-sv"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:autocorr-tr"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:autocorr-vi"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:autocorr-zh"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:libreoffice"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:libreoffice-base"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:libreoffice-bsh"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:libreoffice-calc"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:libreoffice-core"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:libreoffice-data"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:libreoffice-debuginfo"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:libreoffice-draw"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:libreoffice-emailmerge"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:libreoffice-filters"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:libreoffice-gdb-debug-support"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:libreoffice-glade"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:libreoffice-graphicfilter"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:libreoffice-gtk2"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:libreoffice-gtk3"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:libreoffice-help-ar"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:libreoffice-help-bg"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:libreoffice-help-bn"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:libreoffice-help-ca"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:libreoffice-help-cs"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:libreoffice-help-da"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:libreoffice-help-de"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:libreoffice-help-dz"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:libreoffice-help-el"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:libreoffice-help-es"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:libreoffice-help-et"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:libreoffice-help-eu"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:libreoffice-help-fi"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:libreoffice-help-fr"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:libreoffice-help-gl"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:libreoffice-help-gu"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:libreoffice-help-he"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:libreoffice-help-hi"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:libreoffice-help-hr"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:libreoffice-help-hu"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:libreoffice-help-id"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:libreoffice-help-it"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:libreoffice-help-ja"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:libreoffice-help-ko"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:libreoffice-help-lt"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:libreoffice-help-lv"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:libreoffice-help-nb"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:libreoffice-help-nl"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:libreoffice-help-nn"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:libreoffice-help-pl"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:libreoffice-help-pt-BR"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:libreoffice-help-pt-PT"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:libreoffice-help-ro"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:libreoffice-help-ru"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:libreoffice-help-si"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:libreoffice-help-sk"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:libreoffice-help-sl"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:libreoffice-help-sv"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:libreoffice-help-ta"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:libreoffice-help-tr"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:libreoffice-help-uk"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:libreoffice-help-zh-Hans"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:libreoffice-help-zh-Hant"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:libreoffice-impress"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:libreoffice-langpack-af"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:libreoffice-langpack-ar"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:libreoffice-langpack-as"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:libreoffice-langpack-bg"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:libreoffice-langpack-bn"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:libreoffice-langpack-br"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:libreoffice-langpack-ca"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:libreoffice-langpack-cs"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:libreoffice-langpack-cy"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:libreoffice-langpack-da"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:libreoffice-langpack-de"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:libreoffice-langpack-dz"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:libreoffice-langpack-el"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:libreoffice-langpack-en"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:libreoffice-langpack-es"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:libreoffice-langpack-et"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:libreoffice-langpack-eu"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:libreoffice-langpack-fa"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:libreoffice-langpack-fi"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:libreoffice-langpack-fr"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:libreoffice-langpack-ga"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:libreoffice-langpack-gl"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:libreoffice-langpack-gu"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:libreoffice-langpack-he"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:libreoffice-langpack-hi"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:libreoffice-langpack-hr"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:libreoffice-langpack-hu"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:libreoffice-langpack-id"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:libreoffice-langpack-it"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:libreoffice-langpack-ja"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:libreoffice-langpack-kk"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:libreoffice-langpack-kn"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:libreoffice-langpack-ko"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:libreoffice-langpack-lt"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:libreoffice-langpack-lv"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:libreoffice-langpack-mai"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:libreoffice-langpack-ml"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:libreoffice-langpack-mr"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:libreoffice-langpack-nb"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:libreoffice-langpack-nl"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:libreoffice-langpack-nn"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:libreoffice-langpack-nr"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:libreoffice-langpack-nso"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:libreoffice-langpack-or"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:libreoffice-langpack-pa"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:libreoffice-langpack-pl"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:libreoffice-langpack-pt-BR"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:libreoffice-langpack-pt-PT"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:libreoffice-langpack-ro"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:libreoffice-langpack-ru"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:libreoffice-langpack-si"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:libreoffice-langpack-sk"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:libreoffice-langpack-sl"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:libreoffice-langpack-sr"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:libreoffice-langpack-ss"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:libreoffice-langpack-st"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:libreoffice-langpack-sv"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:libreoffice-langpack-ta"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:libreoffice-langpack-te"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:libreoffice-langpack-th"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:libreoffice-langpack-tn"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:libreoffice-langpack-tr"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:libreoffice-langpack-ts"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:libreoffice-langpack-uk"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:libreoffice-langpack-ve"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:libreoffice-langpack-xh"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:libreoffice-langpack-zh-Hans"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:libreoffice-langpack-zh-Hant"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:libreoffice-langpack-zu"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:libreoffice-librelogo"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:libreoffice-math"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:libreoffice-nlpsolver"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:libreoffice-officebean"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:libreoffice-officebean-common"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:libreoffice-ogltrans"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:libreoffice-opensymbol-fonts"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:libreoffice-pdfimport"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:libreoffice-postgresql"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:libreoffice-pyuno"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:libreoffice-rhino"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:libreoffice-sdk"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:libreoffice-sdk-doc"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:libreoffice-ure"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:libreoffice-ure-common"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:libreoffice-wiki-publisher"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:libreoffice-writer"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:libreoffice-x11"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:libreoffice-xsltfilter"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:libreofficekit"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:redhat:enterprise_linux:libreofficekit-devel"); script_set_attribute(attribute:"cpe", value:"cpe:/o:redhat:enterprise_linux:7"); script_set_attribute(attribute:"vuln_publication_date", value:"2018/04/16"); script_set_attribute(attribute:"patch_publication_date", value:"2018/10/30"); script_set_attribute(attribute:"plugin_publication_date", value:"2018/10/31"); script_set_attribute(attribute:"generated_plugin", value:"current"); script_end_attributes(); script_category(ACT_GATHER_INFO); script_copyright(english:"This script is Copyright (C) 2018-2019 and is owned by Tenable, Inc. or an Affiliate thereof."); script_family(english:"Red Hat Local Security Checks"); script_dependencies("ssh_get_info.nasl"); script_require_keys("Host/local_checks_enabled", "Host/RedHat/release", "Host/RedHat/rpm-list", "Host/cpu"); exit(0); } include("audit.inc"); include("global_settings.inc"); include("misc_func.inc"); include("rpm.inc"); if (!get_kb_item("Host/local_checks_enabled")) audit(AUDIT_LOCAL_CHECKS_NOT_ENABLED); release = get_kb_item("Host/RedHat/release"); if (isnull(release) || "Red Hat" >!< release) audit(AUDIT_OS_NOT, "Red Hat"); os_ver = pregmatch(pattern: "Red Hat Enterprise Linux.*release ([0-9]+(\.[0-9]+)?)", string:release); if (isnull(os_ver)) audit(AUDIT_UNKNOWN_APP_VER, "Red Hat"); os_ver = os_ver[1]; if (! preg(pattern:"^7([^0-9]|$)", string:os_ver)) audit(AUDIT_OS_NOT, "Red Hat 7.x", "Red Hat " + os_ver); if (!get_kb_item("Host/RedHat/rpm-list")) audit(AUDIT_PACKAGE_LIST_MISSING); cpu = get_kb_item("Host/cpu"); if (isnull(cpu)) audit(AUDIT_UNKNOWN_ARCH); if ("x86_64" >!< cpu && cpu !~ "^i[3-6]86$" && "s390" >!< cpu) audit(AUDIT_LOCAL_CHECKS_NOT_IMPLEMENTED, "Red Hat", cpu); yum_updateinfo = get_kb_item("Host/RedHat/yum-updateinfo"); if (!empty_or_null(yum_updateinfo)) { rhsa = "RHSA-2018:3054"; yum_report = redhat_generate_yum_updateinfo_report(rhsa:rhsa); if (!empty_or_null(yum_report)) { security_report_v4( port : 0, severity : SECURITY_WARNING, extra : yum_report ); exit(0); } else { audit_message = "affected by Red Hat security advisory " + rhsa; audit(AUDIT_OS_NOT, audit_message); } } else { flag = 0; if (rpm_check(release:"RHEL7", reference:"autocorr-af-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"RHEL7", reference:"autocorr-bg-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"RHEL7", reference:"autocorr-ca-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"RHEL7", reference:"autocorr-cs-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"RHEL7", reference:"autocorr-da-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"RHEL7", reference:"autocorr-de-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"RHEL7", reference:"autocorr-en-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"RHEL7", reference:"autocorr-es-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"RHEL7", reference:"autocorr-fa-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"RHEL7", reference:"autocorr-fi-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"RHEL7", reference:"autocorr-fr-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"RHEL7", reference:"autocorr-ga-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"RHEL7", reference:"autocorr-hr-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"RHEL7", reference:"autocorr-hu-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"RHEL7", reference:"autocorr-is-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"RHEL7", reference:"autocorr-it-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"RHEL7", reference:"autocorr-ja-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"RHEL7", reference:"autocorr-ko-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"RHEL7", reference:"autocorr-lb-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"RHEL7", reference:"autocorr-lt-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"RHEL7", reference:"autocorr-mn-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"RHEL7", reference:"autocorr-nl-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"RHEL7", reference:"autocorr-pl-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"RHEL7", reference:"autocorr-pt-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"RHEL7", reference:"autocorr-ro-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"RHEL7", reference:"autocorr-ru-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"RHEL7", reference:"autocorr-sk-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"RHEL7", reference:"autocorr-sl-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"RHEL7", reference:"autocorr-sr-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"RHEL7", reference:"autocorr-sv-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"RHEL7", reference:"autocorr-tr-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"RHEL7", reference:"autocorr-vi-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"RHEL7", reference:"autocorr-zh-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"RHEL7", cpu:"x86_64", reference:"libreoffice-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"RHEL7", cpu:"x86_64", reference:"libreoffice-base-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"RHEL7", cpu:"x86_64", reference:"libreoffice-bsh-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"RHEL7", cpu:"x86_64", reference:"libreoffice-calc-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"RHEL7", cpu:"x86_64", reference:"libreoffice-core-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"RHEL7", reference:"libreoffice-data-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"RHEL7", cpu:"x86_64", reference:"libreoffice-debuginfo-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"RHEL7", cpu:"x86_64", reference:"libreoffice-draw-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"RHEL7", cpu:"x86_64", reference:"libreoffice-emailmerge-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"RHEL7", cpu:"x86_64", reference:"libreoffice-filters-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"RHEL7", cpu:"x86_64", reference:"libreoffice-gdb-debug-support-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"RHEL7", cpu:"x86_64", reference:"libreoffice-glade-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"RHEL7", cpu:"x86_64", reference:"libreoffice-graphicfilter-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"RHEL7", cpu:"x86_64", reference:"libreoffice-gtk2-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"RHEL7", cpu:"x86_64", reference:"libreoffice-gtk3-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"RHEL7", cpu:"x86_64", reference:"libreoffice-help-ar-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"RHEL7", cpu:"x86_64", reference:"libreoffice-help-bg-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"RHEL7", cpu:"x86_64", reference:"libreoffice-help-bn-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"RHEL7", cpu:"x86_64", reference:"libreoffice-help-ca-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"RHEL7", cpu:"x86_64", reference:"libreoffice-help-cs-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"RHEL7", cpu:"x86_64", reference:"libreoffice-help-da-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"RHEL7", cpu:"x86_64", reference:"libreoffice-help-de-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"RHEL7", cpu:"x86_64", reference:"libreoffice-help-dz-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"RHEL7", cpu:"x86_64", reference:"libreoffice-help-el-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"RHEL7", cpu:"x86_64", reference:"libreoffice-help-es-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"RHEL7", cpu:"x86_64", reference:"libreoffice-help-et-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"RHEL7", cpu:"x86_64", reference:"libreoffice-help-eu-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"RHEL7", cpu:"x86_64", reference:"libreoffice-help-fi-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"RHEL7", cpu:"x86_64", reference:"libreoffice-help-fr-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"RHEL7", cpu:"x86_64", reference:"libreoffice-help-gl-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"RHEL7", cpu:"x86_64", reference:"libreoffice-help-gu-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"RHEL7", cpu:"x86_64", reference:"libreoffice-help-he-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"RHEL7", cpu:"x86_64", reference:"libreoffice-help-hi-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"RHEL7", cpu:"x86_64", reference:"libreoffice-help-hr-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"RHEL7", cpu:"x86_64", reference:"libreoffice-help-hu-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"RHEL7", cpu:"x86_64", reference:"libreoffice-help-id-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"RHEL7", cpu:"x86_64", reference:"libreoffice-help-it-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"RHEL7", cpu:"x86_64", reference:"libreoffice-help-ja-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"RHEL7", cpu:"x86_64", reference:"libreoffice-help-ko-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"RHEL7", cpu:"x86_64", reference:"libreoffice-help-lt-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"RHEL7", cpu:"x86_64", reference:"libreoffice-help-lv-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"RHEL7", cpu:"x86_64", reference:"libreoffice-help-nb-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"RHEL7", cpu:"x86_64", reference:"libreoffice-help-nl-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"RHEL7", cpu:"x86_64", reference:"libreoffice-help-nn-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"RHEL7", cpu:"x86_64", reference:"libreoffice-help-pl-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"RHEL7", cpu:"x86_64", reference:"libreoffice-help-pt-BR-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"RHEL7", cpu:"x86_64", reference:"libreoffice-help-pt-PT-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"RHEL7", cpu:"x86_64", reference:"libreoffice-help-ro-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"RHEL7", cpu:"x86_64", reference:"libreoffice-help-ru-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"RHEL7", cpu:"x86_64", reference:"libreoffice-help-si-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"RHEL7", cpu:"x86_64", reference:"libreoffice-help-sk-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"RHEL7", cpu:"x86_64", reference:"libreoffice-help-sl-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"RHEL7", cpu:"x86_64", reference:"libreoffice-help-sv-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"RHEL7", cpu:"x86_64", reference:"libreoffice-help-ta-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"RHEL7", cpu:"x86_64", reference:"libreoffice-help-tr-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"RHEL7", cpu:"x86_64", reference:"libreoffice-help-uk-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"RHEL7", cpu:"x86_64", reference:"libreoffice-help-zh-Hans-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"RHEL7", cpu:"x86_64", reference:"libreoffice-help-zh-Hant-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"RHEL7", cpu:"x86_64", reference:"libreoffice-impress-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"RHEL7", cpu:"x86_64", reference:"libreoffice-langpack-af-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"RHEL7", cpu:"x86_64", reference:"libreoffice-langpack-ar-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"RHEL7", cpu:"x86_64", reference:"libreoffice-langpack-as-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"RHEL7", cpu:"x86_64", reference:"libreoffice-langpack-bg-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"RHEL7", cpu:"x86_64", reference:"libreoffice-langpack-bn-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"RHEL7", cpu:"x86_64", reference:"libreoffice-langpack-br-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"RHEL7", cpu:"x86_64", reference:"libreoffice-langpack-ca-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"RHEL7", cpu:"x86_64", reference:"libreoffice-langpack-cs-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"RHEL7", cpu:"x86_64", reference:"libreoffice-langpack-cy-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"RHEL7", cpu:"x86_64", reference:"libreoffice-langpack-da-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"RHEL7", cpu:"x86_64", reference:"libreoffice-langpack-de-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"RHEL7", cpu:"x86_64", reference:"libreoffice-langpack-dz-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"RHEL7", cpu:"x86_64", reference:"libreoffice-langpack-el-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"RHEL7", cpu:"x86_64", reference:"libreoffice-langpack-en-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"RHEL7", cpu:"x86_64", reference:"libreoffice-langpack-es-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"RHEL7", cpu:"x86_64", reference:"libreoffice-langpack-et-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"RHEL7", cpu:"x86_64", reference:"libreoffice-langpack-eu-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"RHEL7", cpu:"x86_64", reference:"libreoffice-langpack-fa-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"RHEL7", cpu:"x86_64", reference:"libreoffice-langpack-fi-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"RHEL7", cpu:"x86_64", reference:"libreoffice-langpack-fr-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"RHEL7", cpu:"x86_64", reference:"libreoffice-langpack-ga-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"RHEL7", cpu:"x86_64", reference:"libreoffice-langpack-gl-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"RHEL7", cpu:"x86_64", reference:"libreoffice-langpack-gu-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"RHEL7", cpu:"x86_64", reference:"libreoffice-langpack-he-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"RHEL7", cpu:"x86_64", reference:"libreoffice-langpack-hi-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"RHEL7", cpu:"x86_64", reference:"libreoffice-langpack-hr-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"RHEL7", cpu:"x86_64", reference:"libreoffice-langpack-hu-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"RHEL7", cpu:"x86_64", reference:"libreoffice-langpack-id-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"RHEL7", cpu:"x86_64", reference:"libreoffice-langpack-it-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"RHEL7", cpu:"x86_64", reference:"libreoffice-langpack-ja-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"RHEL7", cpu:"x86_64", reference:"libreoffice-langpack-kk-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"RHEL7", cpu:"x86_64", reference:"libreoffice-langpack-kn-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"RHEL7", cpu:"x86_64", reference:"libreoffice-langpack-ko-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"RHEL7", cpu:"x86_64", reference:"libreoffice-langpack-lt-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"RHEL7", cpu:"x86_64", reference:"libreoffice-langpack-lv-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"RHEL7", cpu:"x86_64", reference:"libreoffice-langpack-mai-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"RHEL7", cpu:"x86_64", reference:"libreoffice-langpack-ml-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"RHEL7", cpu:"x86_64", reference:"libreoffice-langpack-mr-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"RHEL7", cpu:"x86_64", reference:"libreoffice-langpack-nb-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"RHEL7", cpu:"x86_64", reference:"libreoffice-langpack-nl-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"RHEL7", cpu:"x86_64", reference:"libreoffice-langpack-nn-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"RHEL7", cpu:"x86_64", reference:"libreoffice-langpack-nr-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"RHEL7", cpu:"x86_64", reference:"libreoffice-langpack-nso-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"RHEL7", cpu:"x86_64", reference:"libreoffice-langpack-or-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"RHEL7", cpu:"x86_64", reference:"libreoffice-langpack-pa-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"RHEL7", cpu:"x86_64", reference:"libreoffice-langpack-pl-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"RHEL7", cpu:"x86_64", reference:"libreoffice-langpack-pt-BR-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"RHEL7", cpu:"x86_64", reference:"libreoffice-langpack-pt-PT-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"RHEL7", cpu:"x86_64", reference:"libreoffice-langpack-ro-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"RHEL7", cpu:"x86_64", reference:"libreoffice-langpack-ru-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"RHEL7", cpu:"x86_64", reference:"libreoffice-langpack-si-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"RHEL7", cpu:"x86_64", reference:"libreoffice-langpack-sk-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"RHEL7", cpu:"x86_64", reference:"libreoffice-langpack-sl-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"RHEL7", cpu:"x86_64", reference:"libreoffice-langpack-sr-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"RHEL7", cpu:"x86_64", reference:"libreoffice-langpack-ss-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"RHEL7", cpu:"x86_64", reference:"libreoffice-langpack-st-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"RHEL7", cpu:"x86_64", reference:"libreoffice-langpack-sv-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"RHEL7", cpu:"x86_64", reference:"libreoffice-langpack-ta-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"RHEL7", cpu:"x86_64", reference:"libreoffice-langpack-te-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"RHEL7", cpu:"x86_64", reference:"libreoffice-langpack-th-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"RHEL7", cpu:"x86_64", reference:"libreoffice-langpack-tn-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"RHEL7", cpu:"x86_64", reference:"libreoffice-langpack-tr-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"RHEL7", cpu:"x86_64", reference:"libreoffice-langpack-ts-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"RHEL7", cpu:"x86_64", reference:"libreoffice-langpack-uk-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"RHEL7", cpu:"x86_64", reference:"libreoffice-langpack-ve-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"RHEL7", cpu:"x86_64", reference:"libreoffice-langpack-xh-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"RHEL7", cpu:"x86_64", reference:"libreoffice-langpack-zh-Hans-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"RHEL7", cpu:"x86_64", reference:"libreoffice-langpack-zh-Hant-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"RHEL7", cpu:"x86_64", reference:"libreoffice-langpack-zu-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"RHEL7", cpu:"x86_64", reference:"libreoffice-librelogo-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"RHEL7", cpu:"x86_64", reference:"libreoffice-math-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"RHEL7", cpu:"x86_64", reference:"libreoffice-nlpsolver-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"RHEL7", cpu:"x86_64", reference:"libreoffice-officebean-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"RHEL7", reference:"libreoffice-officebean-common-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"RHEL7", cpu:"x86_64", reference:"libreoffice-ogltrans-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"RHEL7", reference:"libreoffice-opensymbol-fonts-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"RHEL7", cpu:"x86_64", reference:"libreoffice-pdfimport-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"RHEL7", cpu:"x86_64", reference:"libreoffice-postgresql-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"RHEL7", cpu:"x86_64", reference:"libreoffice-pyuno-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"RHEL7", cpu:"x86_64", reference:"libreoffice-rhino-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"RHEL7", cpu:"x86_64", reference:"libreoffice-sdk-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"RHEL7", cpu:"x86_64", reference:"libreoffice-sdk-doc-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"RHEL7", cpu:"x86_64", reference:"libreoffice-ure-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"RHEL7", reference:"libreoffice-ure-common-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"RHEL7", cpu:"x86_64", reference:"libreoffice-wiki-publisher-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"RHEL7", cpu:"x86_64", reference:"libreoffice-writer-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"RHEL7", cpu:"x86_64", reference:"libreoffice-x11-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"RHEL7", cpu:"x86_64", reference:"libreoffice-xsltfilter-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"RHEL7", cpu:"x86_64", reference:"libreofficekit-5.3.6.1-19.el7")) flag++; if (rpm_check(release:"RHEL7", cpu:"x86_64", reference:"libreofficekit-devel-5.3.6.1-19.el7")) flag++; if (flag) { security_report_v4( port : 0, severity : SECURITY_WARNING, extra : rpm_report_get() + redhat_report_package_caveat() ); exit(0); } else { tested = pkg_tests_get(); if (tested) audit(AUDIT_PACKAGE_NOT_AFFECTED, tested); else audit(AUDIT_PACKAGE_NOT_INSTALLED, "autocorr-af / autocorr-bg / autocorr-ca / autocorr-cs / autocorr-da / etc"); } }
NASL family SuSE Local Security Checks NASL id OPENSUSE-2018-467.NASL description This update for libreoffice to 6.0.4.2 fixes lots of bugs and also the following issues : Security issues fixed : - CVE-2018-10120: The SwCTBWrapper::Read function in sw/source/filter/ww8/ww8toolbar.cxx did not validate a customizations index, which allowed remote attackers to cause a denial of service (heap-based buffer overflow with write access) or possibly have unspecified other impact via a crafted document that contains a certain Microsoft Word record. (bsc#1089706) - CVE-2018-10119: sot/source/sdstor/stgstrms.cxx used an incorrect integer data type in the StgSmallStrm class, which allowed remote attackers to cause a denial of service (use-after-free with write access) or possibly have unspecified other impact via a crafted document that uses the structured storage ole2 wrapper file format. (bsc#1089705) Other issues fixed : - DOCX import: missing table background color - Bring back offline help per popular demand as lto saves space we could use with it bsc#915996 This update was imported from the SUSE:SLE-12-SP3:Update update project. last seen 2020-06-05 modified 2018-05-17 plugin id 109880 published 2018-05-17 reporter This script is Copyright (C) 2018-2020 and is owned by Tenable, Inc. or an Affiliate thereof. source https://www.tenable.com/plugins/nessus/109880 title openSUSE Security Update : libreoffice (openSUSE-2018-467) code #%NASL_MIN_LEVEL 80502 # # (C) Tenable Network Security, Inc. # # The descriptive text and package checks in this plugin were # extracted from openSUSE Security Update openSUSE-2018-467. # # The text description of this plugin is (C) SUSE LLC. # include("compat.inc"); if (description) { script_id(109880); script_version("1.4"); script_set_attribute(attribute:"plugin_modification_date", value:"2020/06/04"); script_cve_id("CVE-2018-10119", "CVE-2018-10120"); script_name(english:"openSUSE Security Update : libreoffice (openSUSE-2018-467)"); script_summary(english:"Check for the openSUSE-2018-467 patch"); script_set_attribute( attribute:"synopsis", value:"The remote openSUSE host is missing a security update." ); script_set_attribute( attribute:"description", value: "This update for libreoffice to 6.0.4.2 fixes lots of bugs and also the following issues : Security issues fixed : - CVE-2018-10120: The SwCTBWrapper::Read function in sw/source/filter/ww8/ww8toolbar.cxx did not validate a customizations index, which allowed remote attackers to cause a denial of service (heap-based buffer overflow with write access) or possibly have unspecified other impact via a crafted document that contains a certain Microsoft Word record. (bsc#1089706) - CVE-2018-10119: sot/source/sdstor/stgstrms.cxx used an incorrect integer data type in the StgSmallStrm class, which allowed remote attackers to cause a denial of service (use-after-free with write access) or possibly have unspecified other impact via a crafted document that uses the structured storage ole2 wrapper file format. (bsc#1089705) Other issues fixed : - DOCX import: missing table background color - Bring back offline help per popular demand as lto saves space we could use with it bsc#915996 This update was imported from the SUSE:SLE-12-SP3:Update update project." ); script_set_attribute( attribute:"see_also", value:"https://bugzilla.opensuse.org/show_bug.cgi?id=1089705" ); script_set_attribute( attribute:"see_also", value:"https://bugzilla.opensuse.org/show_bug.cgi?id=1089706" ); script_set_attribute( attribute:"see_also", value:"https://bugzilla.opensuse.org/show_bug.cgi?id=1090737" ); script_set_attribute( attribute:"see_also", value:"https://bugzilla.opensuse.org/show_bug.cgi?id=1091772" ); script_set_attribute( attribute:"see_also", value:"https://bugzilla.opensuse.org/show_bug.cgi?id=915996" ); script_set_attribute( attribute:"solution", value:"Update the affected libreoffice packages." ); script_set_cvss_base_vector("CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P"); script_set_cvss3_base_vector("CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"); script_set_attribute(attribute:"plugin_type", value:"local"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:novell:opensuse:libreoffice"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:novell:opensuse:libreoffice-base"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:novell:opensuse:libreoffice-base-debuginfo"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:novell:opensuse:libreoffice-base-drivers-mysql"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:novell:opensuse:libreoffice-base-drivers-mysql-debuginfo"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:novell:opensuse:libreoffice-base-drivers-postgresql"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:novell:opensuse:libreoffice-base-drivers-postgresql-debuginfo"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:novell:opensuse:libreoffice-branding-upstream"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:novell:opensuse:libreoffice-calc"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:novell:opensuse:libreoffice-calc-debuginfo"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:novell:opensuse:libreoffice-calc-extensions"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:novell:opensuse:libreoffice-debuginfo"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:novell:opensuse:libreoffice-debugsource"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:novell:opensuse:libreoffice-draw"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:novell:opensuse:libreoffice-draw-debuginfo"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:novell:opensuse:libreoffice-filters-optional"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:novell:opensuse:libreoffice-gdb-pretty-printers"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:novell:opensuse:libreoffice-glade"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:novell:opensuse:libreoffice-gnome"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:novell:opensuse:libreoffice-gnome-debuginfo"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:novell:opensuse:libreoffice-gtk2"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:novell:opensuse:libreoffice-gtk2-debuginfo"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:novell:opensuse:libreoffice-gtk3"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:novell:opensuse:libreoffice-gtk3-debuginfo"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:novell:opensuse:libreoffice-icon-themes"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:novell:opensuse:libreoffice-impress"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:novell:opensuse:libreoffice-impress-debuginfo"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:novell:opensuse:libreoffice-kde4"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:novell:opensuse:libreoffice-kde4-debuginfo"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:novell:opensuse:libreoffice-l10n-af"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:novell:opensuse:libreoffice-l10n-ar"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:novell:opensuse:libreoffice-l10n-as"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:novell:opensuse:libreoffice-l10n-bg"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:novell:opensuse:libreoffice-l10n-bn"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:novell:opensuse:libreoffice-l10n-br"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:novell:opensuse:libreoffice-l10n-ca"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:novell:opensuse:libreoffice-l10n-cs"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:novell:opensuse:libreoffice-l10n-cy"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:novell:opensuse:libreoffice-l10n-da"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:novell:opensuse:libreoffice-l10n-de"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:novell:opensuse:libreoffice-l10n-dz"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:novell:opensuse:libreoffice-l10n-el"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:novell:opensuse:libreoffice-l10n-en"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:novell:opensuse:libreoffice-l10n-eo"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:novell:opensuse:libreoffice-l10n-es"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:novell:opensuse:libreoffice-l10n-et"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:novell:opensuse:libreoffice-l10n-eu"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:novell:opensuse:libreoffice-l10n-fa"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:novell:opensuse:libreoffice-l10n-fi"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:novell:opensuse:libreoffice-l10n-fr"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:novell:opensuse:libreoffice-l10n-ga"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:novell:opensuse:libreoffice-l10n-gl"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:novell:opensuse:libreoffice-l10n-gu"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:novell:opensuse:libreoffice-l10n-he"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:novell:opensuse:libreoffice-l10n-hi"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:novell:opensuse:libreoffice-l10n-hr"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:novell:opensuse:libreoffice-l10n-hu"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:novell:opensuse:libreoffice-l10n-it"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:novell:opensuse:libreoffice-l10n-ja"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:novell:opensuse:libreoffice-l10n-kk"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:novell:opensuse:libreoffice-l10n-kn"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:novell:opensuse:libreoffice-l10n-ko"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:novell:opensuse:libreoffice-l10n-lt"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:novell:opensuse:libreoffice-l10n-lv"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:novell:opensuse:libreoffice-l10n-mai"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:novell:opensuse:libreoffice-l10n-ml"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:novell:opensuse:libreoffice-l10n-mr"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:novell:opensuse:libreoffice-l10n-nb"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:novell:opensuse:libreoffice-l10n-nl"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:novell:opensuse:libreoffice-l10n-nn"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:novell:opensuse:libreoffice-l10n-nr"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:novell:opensuse:libreoffice-l10n-nso"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:novell:opensuse:libreoffice-l10n-or"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:novell:opensuse:libreoffice-l10n-pa"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:novell:opensuse:libreoffice-l10n-pl"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:novell:opensuse:libreoffice-l10n-pt_BR"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:novell:opensuse:libreoffice-l10n-pt_PT"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:novell:opensuse:libreoffice-l10n-ro"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:novell:opensuse:libreoffice-l10n-ru"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:novell:opensuse:libreoffice-l10n-si"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:novell:opensuse:libreoffice-l10n-sk"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:novell:opensuse:libreoffice-l10n-sl"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:novell:opensuse:libreoffice-l10n-sr"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:novell:opensuse:libreoffice-l10n-ss"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:novell:opensuse:libreoffice-l10n-st"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:novell:opensuse:libreoffice-l10n-sv"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:novell:opensuse:libreoffice-l10n-ta"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:novell:opensuse:libreoffice-l10n-te"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:novell:opensuse:libreoffice-l10n-th"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:novell:opensuse:libreoffice-l10n-tn"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:novell:opensuse:libreoffice-l10n-tr"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:novell:opensuse:libreoffice-l10n-ts"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:novell:opensuse:libreoffice-l10n-uk"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:novell:opensuse:libreoffice-l10n-ve"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:novell:opensuse:libreoffice-l10n-xh"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:novell:opensuse:libreoffice-l10n-zh_CN"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:novell:opensuse:libreoffice-l10n-zh_TW"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:novell:opensuse:libreoffice-l10n-zu"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:novell:opensuse:libreoffice-mailmerge"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:novell:opensuse:libreoffice-math"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:novell:opensuse:libreoffice-math-debuginfo"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:novell:opensuse:libreoffice-officebean"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:novell:opensuse:libreoffice-officebean-debuginfo"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:novell:opensuse:libreoffice-pyuno"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:novell:opensuse:libreoffice-pyuno-debuginfo"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:novell:opensuse:libreoffice-sdk"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:novell:opensuse:libreoffice-sdk-debuginfo"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:novell:opensuse:libreoffice-writer"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:novell:opensuse:libreoffice-writer-debuginfo"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:novell:opensuse:libreoffice-writer-extensions"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:novell:opensuse:libreofficekit"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:novell:opensuse:libreofficekit-devel"); script_set_attribute(attribute:"cpe", value:"cpe:/o:novell:opensuse:42.3"); script_set_attribute(attribute:"patch_publication_date", value:"2018/05/16"); script_set_attribute(attribute:"plugin_publication_date", value:"2018/05/17"); script_end_attributes(); script_category(ACT_GATHER_INFO); script_copyright(english:"This script is Copyright (C) 2018-2020 and is owned by Tenable, Inc. or an Affiliate thereof."); script_family(english:"SuSE Local Security Checks"); script_dependencies("ssh_get_info.nasl"); script_require_keys("Host/local_checks_enabled", "Host/SuSE/release", "Host/SuSE/rpm-list", "Host/cpu"); exit(0); } include("audit.inc"); include("global_settings.inc"); include("rpm.inc"); if (!get_kb_item("Host/local_checks_enabled")) audit(AUDIT_LOCAL_CHECKS_NOT_ENABLED); release = get_kb_item("Host/SuSE/release"); if (isnull(release) || release =~ "^(SLED|SLES)") audit(AUDIT_OS_NOT, "openSUSE"); if (release !~ "^(SUSE42\.3)$") audit(AUDIT_OS_RELEASE_NOT, "openSUSE", "42.3", release); if (!get_kb_item("Host/SuSE/rpm-list")) audit(AUDIT_PACKAGE_LIST_MISSING); ourarch = get_kb_item("Host/cpu"); if (!ourarch) audit(AUDIT_UNKNOWN_ARCH); if (ourarch !~ "^(x86_64)$") audit(AUDIT_ARCH_NOT, "x86_64", ourarch); flag = 0; if ( rpm_check(release:"SUSE42.3", reference:"libreoffice-6.0.4.2-21.1") ) flag++; if ( rpm_check(release:"SUSE42.3", reference:"libreoffice-base-6.0.4.2-21.1") ) flag++; if ( rpm_check(release:"SUSE42.3", reference:"libreoffice-base-debuginfo-6.0.4.2-21.1") ) flag++; if ( rpm_check(release:"SUSE42.3", reference:"libreoffice-base-drivers-mysql-6.0.4.2-21.1") ) flag++; if ( rpm_check(release:"SUSE42.3", reference:"libreoffice-base-drivers-mysql-debuginfo-6.0.4.2-21.1") ) flag++; if ( rpm_check(release:"SUSE42.3", reference:"libreoffice-base-drivers-postgresql-6.0.4.2-21.1") ) flag++; if ( rpm_check(release:"SUSE42.3", reference:"libreoffice-base-drivers-postgresql-debuginfo-6.0.4.2-21.1") ) flag++; if ( rpm_check(release:"SUSE42.3", reference:"libreoffice-branding-upstream-6.0.4.2-21.1") ) flag++; if ( rpm_check(release:"SUSE42.3", reference:"libreoffice-calc-6.0.4.2-21.1") ) flag++; if ( rpm_check(release:"SUSE42.3", reference:"libreoffice-calc-debuginfo-6.0.4.2-21.1") ) flag++; if ( rpm_check(release:"SUSE42.3", reference:"libreoffice-calc-extensions-6.0.4.2-21.1") ) flag++; if ( rpm_check(release:"SUSE42.3", reference:"libreoffice-debuginfo-6.0.4.2-21.1") ) flag++; if ( rpm_check(release:"SUSE42.3", reference:"libreoffice-debugsource-6.0.4.2-21.1") ) flag++; if ( rpm_check(release:"SUSE42.3", reference:"libreoffice-draw-6.0.4.2-21.1") ) flag++; if ( rpm_check(release:"SUSE42.3", reference:"libreoffice-draw-debuginfo-6.0.4.2-21.1") ) flag++; if ( rpm_check(release:"SUSE42.3", reference:"libreoffice-filters-optional-6.0.4.2-21.1") ) flag++; if ( rpm_check(release:"SUSE42.3", reference:"libreoffice-gdb-pretty-printers-6.0.4.2-21.1") ) flag++; if ( rpm_check(release:"SUSE42.3", reference:"libreoffice-glade-6.0.4.2-21.1") ) flag++; if ( rpm_check(release:"SUSE42.3", reference:"libreoffice-gnome-6.0.4.2-21.1") ) flag++; if ( rpm_check(release:"SUSE42.3", reference:"libreoffice-gnome-debuginfo-6.0.4.2-21.1") ) flag++; if ( rpm_check(release:"SUSE42.3", reference:"libreoffice-gtk2-6.0.4.2-21.1") ) flag++; if ( rpm_check(release:"SUSE42.3", reference:"libreoffice-gtk2-debuginfo-6.0.4.2-21.1") ) flag++; if ( rpm_check(release:"SUSE42.3", reference:"libreoffice-gtk3-6.0.4.2-21.1") ) flag++; if ( rpm_check(release:"SUSE42.3", reference:"libreoffice-gtk3-debuginfo-6.0.4.2-21.1") ) flag++; if ( rpm_check(release:"SUSE42.3", reference:"libreoffice-icon-themes-6.0.4.2-21.1") ) flag++; if ( rpm_check(release:"SUSE42.3", reference:"libreoffice-impress-6.0.4.2-21.1") ) flag++; if ( rpm_check(release:"SUSE42.3", reference:"libreoffice-impress-debuginfo-6.0.4.2-21.1") ) flag++; if ( rpm_check(release:"SUSE42.3", reference:"libreoffice-kde4-6.0.4.2-21.1") ) flag++; if ( rpm_check(release:"SUSE42.3", reference:"libreoffice-kde4-debuginfo-6.0.4.2-21.1") ) flag++; if ( rpm_check(release:"SUSE42.3", reference:"libreoffice-l10n-af-6.0.4.2-21.1") ) flag++; if ( rpm_check(release:"SUSE42.3", reference:"libreoffice-l10n-ar-6.0.4.2-21.1") ) flag++; if ( rpm_check(release:"SUSE42.3", reference:"libreoffice-l10n-as-6.0.4.2-21.1") ) flag++; if ( rpm_check(release:"SUSE42.3", reference:"libreoffice-l10n-bg-6.0.4.2-21.1") ) flag++; if ( rpm_check(release:"SUSE42.3", reference:"libreoffice-l10n-bn-6.0.4.2-21.1") ) flag++; if ( rpm_check(release:"SUSE42.3", reference:"libreoffice-l10n-br-6.0.4.2-21.1") ) flag++; if ( rpm_check(release:"SUSE42.3", reference:"libreoffice-l10n-ca-6.0.4.2-21.1") ) flag++; if ( rpm_check(release:"SUSE42.3", reference:"libreoffice-l10n-cs-6.0.4.2-21.1") ) flag++; if ( rpm_check(release:"SUSE42.3", reference:"libreoffice-l10n-cy-6.0.4.2-21.1") ) flag++; if ( rpm_check(release:"SUSE42.3", reference:"libreoffice-l10n-da-6.0.4.2-21.1") ) flag++; if ( rpm_check(release:"SUSE42.3", reference:"libreoffice-l10n-de-6.0.4.2-21.1") ) flag++; if ( rpm_check(release:"SUSE42.3", reference:"libreoffice-l10n-dz-6.0.4.2-21.1") ) flag++; if ( rpm_check(release:"SUSE42.3", reference:"libreoffice-l10n-el-6.0.4.2-21.1") ) flag++; if ( rpm_check(release:"SUSE42.3", reference:"libreoffice-l10n-en-6.0.4.2-21.1") ) flag++; if ( rpm_check(release:"SUSE42.3", reference:"libreoffice-l10n-eo-6.0.4.2-21.1") ) flag++; if ( rpm_check(release:"SUSE42.3", reference:"libreoffice-l10n-es-6.0.4.2-21.1") ) flag++; if ( rpm_check(release:"SUSE42.3", reference:"libreoffice-l10n-et-6.0.4.2-21.1") ) flag++; if ( rpm_check(release:"SUSE42.3", reference:"libreoffice-l10n-eu-6.0.4.2-21.1") ) flag++; if ( rpm_check(release:"SUSE42.3", reference:"libreoffice-l10n-fa-6.0.4.2-21.1") ) flag++; if ( rpm_check(release:"SUSE42.3", reference:"libreoffice-l10n-fi-6.0.4.2-21.1") ) flag++; if ( rpm_check(release:"SUSE42.3", reference:"libreoffice-l10n-fr-6.0.4.2-21.1") ) flag++; if ( rpm_check(release:"SUSE42.3", reference:"libreoffice-l10n-ga-6.0.4.2-21.1") ) flag++; if ( rpm_check(release:"SUSE42.3", reference:"libreoffice-l10n-gl-6.0.4.2-21.1") ) flag++; if ( rpm_check(release:"SUSE42.3", reference:"libreoffice-l10n-gu-6.0.4.2-21.1") ) flag++; if ( rpm_check(release:"SUSE42.3", reference:"libreoffice-l10n-he-6.0.4.2-21.1") ) flag++; if ( rpm_check(release:"SUSE42.3", reference:"libreoffice-l10n-hi-6.0.4.2-21.1") ) flag++; if ( rpm_check(release:"SUSE42.3", reference:"libreoffice-l10n-hr-6.0.4.2-21.1") ) flag++; if ( rpm_check(release:"SUSE42.3", reference:"libreoffice-l10n-hu-6.0.4.2-21.1") ) flag++; if ( rpm_check(release:"SUSE42.3", reference:"libreoffice-l10n-it-6.0.4.2-21.1") ) flag++; if ( rpm_check(release:"SUSE42.3", reference:"libreoffice-l10n-ja-6.0.4.2-21.1") ) flag++; if ( rpm_check(release:"SUSE42.3", reference:"libreoffice-l10n-kk-6.0.4.2-21.1") ) flag++; if ( rpm_check(release:"SUSE42.3", reference:"libreoffice-l10n-kn-6.0.4.2-21.1") ) flag++; if ( rpm_check(release:"SUSE42.3", reference:"libreoffice-l10n-ko-6.0.4.2-21.1") ) flag++; if ( rpm_check(release:"SUSE42.3", reference:"libreoffice-l10n-lt-6.0.4.2-21.1") ) flag++; if ( rpm_check(release:"SUSE42.3", reference:"libreoffice-l10n-lv-6.0.4.2-21.1") ) flag++; if ( rpm_check(release:"SUSE42.3", reference:"libreoffice-l10n-mai-6.0.4.2-21.1") ) flag++; if ( rpm_check(release:"SUSE42.3", reference:"libreoffice-l10n-ml-6.0.4.2-21.1") ) flag++; if ( rpm_check(release:"SUSE42.3", reference:"libreoffice-l10n-mr-6.0.4.2-21.1") ) flag++; if ( rpm_check(release:"SUSE42.3", reference:"libreoffice-l10n-nb-6.0.4.2-21.1") ) flag++; if ( rpm_check(release:"SUSE42.3", reference:"libreoffice-l10n-nl-6.0.4.2-21.1") ) flag++; if ( rpm_check(release:"SUSE42.3", reference:"libreoffice-l10n-nn-6.0.4.2-21.1") ) flag++; if ( rpm_check(release:"SUSE42.3", reference:"libreoffice-l10n-nr-6.0.4.2-21.1") ) flag++; if ( rpm_check(release:"SUSE42.3", reference:"libreoffice-l10n-nso-6.0.4.2-21.1") ) flag++; if ( rpm_check(release:"SUSE42.3", reference:"libreoffice-l10n-or-6.0.4.2-21.1") ) flag++; if ( rpm_check(release:"SUSE42.3", reference:"libreoffice-l10n-pa-6.0.4.2-21.1") ) flag++; if ( rpm_check(release:"SUSE42.3", reference:"libreoffice-l10n-pl-6.0.4.2-21.1") ) flag++; if ( rpm_check(release:"SUSE42.3", reference:"libreoffice-l10n-pt_BR-6.0.4.2-21.1") ) flag++; if ( rpm_check(release:"SUSE42.3", reference:"libreoffice-l10n-pt_PT-6.0.4.2-21.1") ) flag++; if ( rpm_check(release:"SUSE42.3", reference:"libreoffice-l10n-ro-6.0.4.2-21.1") ) flag++; if ( rpm_check(release:"SUSE42.3", reference:"libreoffice-l10n-ru-6.0.4.2-21.1") ) flag++; if ( rpm_check(release:"SUSE42.3", reference:"libreoffice-l10n-si-6.0.4.2-21.1") ) flag++; if ( rpm_check(release:"SUSE42.3", reference:"libreoffice-l10n-sk-6.0.4.2-21.1") ) flag++; if ( rpm_check(release:"SUSE42.3", reference:"libreoffice-l10n-sl-6.0.4.2-21.1") ) flag++; if ( rpm_check(release:"SUSE42.3", reference:"libreoffice-l10n-sr-6.0.4.2-21.1") ) flag++; if ( rpm_check(release:"SUSE42.3", reference:"libreoffice-l10n-ss-6.0.4.2-21.1") ) flag++; if ( rpm_check(release:"SUSE42.3", reference:"libreoffice-l10n-st-6.0.4.2-21.1") ) flag++; if ( rpm_check(release:"SUSE42.3", reference:"libreoffice-l10n-sv-6.0.4.2-21.1") ) flag++; if ( rpm_check(release:"SUSE42.3", reference:"libreoffice-l10n-ta-6.0.4.2-21.1") ) flag++; if ( rpm_check(release:"SUSE42.3", reference:"libreoffice-l10n-te-6.0.4.2-21.1") ) flag++; if ( rpm_check(release:"SUSE42.3", reference:"libreoffice-l10n-th-6.0.4.2-21.1") ) flag++; if ( rpm_check(release:"SUSE42.3", reference:"libreoffice-l10n-tn-6.0.4.2-21.1") ) flag++; if ( rpm_check(release:"SUSE42.3", reference:"libreoffice-l10n-tr-6.0.4.2-21.1") ) flag++; if ( rpm_check(release:"SUSE42.3", reference:"libreoffice-l10n-ts-6.0.4.2-21.1") ) flag++; if ( rpm_check(release:"SUSE42.3", reference:"libreoffice-l10n-uk-6.0.4.2-21.1") ) flag++; if ( rpm_check(release:"SUSE42.3", reference:"libreoffice-l10n-ve-6.0.4.2-21.1") ) flag++; if ( rpm_check(release:"SUSE42.3", reference:"libreoffice-l10n-xh-6.0.4.2-21.1") ) flag++; if ( rpm_check(release:"SUSE42.3", reference:"libreoffice-l10n-zh_CN-6.0.4.2-21.1") ) flag++; if ( rpm_check(release:"SUSE42.3", reference:"libreoffice-l10n-zh_TW-6.0.4.2-21.1") ) flag++; if ( rpm_check(release:"SUSE42.3", reference:"libreoffice-l10n-zu-6.0.4.2-21.1") ) flag++; if ( rpm_check(release:"SUSE42.3", reference:"libreoffice-mailmerge-6.0.4.2-21.1") ) flag++; if ( rpm_check(release:"SUSE42.3", reference:"libreoffice-math-6.0.4.2-21.1") ) flag++; if ( rpm_check(release:"SUSE42.3", reference:"libreoffice-math-debuginfo-6.0.4.2-21.1") ) flag++; if ( rpm_check(release:"SUSE42.3", reference:"libreoffice-officebean-6.0.4.2-21.1") ) flag++; if ( rpm_check(release:"SUSE42.3", reference:"libreoffice-officebean-debuginfo-6.0.4.2-21.1") ) flag++; if ( rpm_check(release:"SUSE42.3", reference:"libreoffice-pyuno-6.0.4.2-21.1") ) flag++; if ( rpm_check(release:"SUSE42.3", reference:"libreoffice-pyuno-debuginfo-6.0.4.2-21.1") ) flag++; if ( rpm_check(release:"SUSE42.3", reference:"libreoffice-sdk-6.0.4.2-21.1") ) flag++; if ( rpm_check(release:"SUSE42.3", reference:"libreoffice-sdk-debuginfo-6.0.4.2-21.1") ) flag++; if ( rpm_check(release:"SUSE42.3", reference:"libreoffice-writer-6.0.4.2-21.1") ) flag++; if ( rpm_check(release:"SUSE42.3", reference:"libreoffice-writer-debuginfo-6.0.4.2-21.1") ) flag++; if ( rpm_check(release:"SUSE42.3", reference:"libreoffice-writer-extensions-6.0.4.2-21.1") ) flag++; if ( rpm_check(release:"SUSE42.3", reference:"libreofficekit-6.0.4.2-21.1") ) flag++; if ( rpm_check(release:"SUSE42.3", reference:"libreofficekit-devel-6.0.4.2-21.1") ) flag++; if (flag) { if (report_verbosity > 0) security_warning(port:0, extra:rpm_report_get()); else security_warning(0); exit(0); } else { tested = pkg_tests_get(); if (tested) audit(AUDIT_PACKAGE_NOT_AFFECTED, tested); else audit(AUDIT_PACKAGE_NOT_INSTALLED, "libreoffice / libreoffice-base / libreoffice-base-debuginfo / etc"); }
NASL family Ubuntu Local Security Checks NASL id UBUNTU_USN-3883-1.NASL description It was discovered that LibreOffice incorrectly handled certain document files. If a user were tricked into opening a specially crafted document, a remote attacker could cause LibreOffice to crash, and possibly execute arbitrary code. (CVE-2018-10119, CVE-2018-10120, CVE-2018-11790) It was discovered that LibreOffice incorrectly handled embedded SMB connections in document files. If a user were tricked in to opening a specially crafted document, a remote attacker could possibly exploit this to obtain sensitive information. (CVE-2018-10583) Alex Infuhr discovered that LibreOffice incorrectly handled embedded scripts in document files. If a user were tricked into opening a specially crafted document, a remote attacker could possibly execute arbitrary code. (CVE-2018-16858). Note that Tenable Network Security has extracted the preceding description block directly from the Ubuntu security advisory. Tenable has attempted to automatically clean and format it as much as possible without introducing additional issues. last seen 2020-06-01 modified 2020-06-02 plugin id 121640 published 2019-02-07 reporter Ubuntu Security Notice (C) 2019 Canonical, Inc. / NASL script (C) 2019 and is owned by Tenable, Inc. or an Affiliate thereof. source https://www.tenable.com/plugins/nessus/121640 title Ubuntu 14.04 LTS / 16.04 LTS : libreoffice vulnerabilities (USN-3883-1) code # # (C) Tenable Network Security, Inc. # # The descriptive text and package checks in this plugin were # extracted from Ubuntu Security Notice USN-3883-1. The text # itself is copyright (C) Canonical, Inc. See # <http://www.ubuntu.com/usn/>. Ubuntu(R) is a registered # trademark of Canonical, Inc. # include("compat.inc"); if (description) { script_id(121640); script_version("1.11"); script_cvs_date("Date: 2019/09/18 12:31:49"); script_cve_id("CVE-2018-10119", "CVE-2018-10120", "CVE-2018-10583", "CVE-2018-11790", "CVE-2018-16858"); script_xref(name:"USN", value:"3883-1"); script_name(english:"Ubuntu 14.04 LTS / 16.04 LTS : libreoffice vulnerabilities (USN-3883-1)"); script_summary(english:"Checks dpkg output for updated package."); script_set_attribute( attribute:"synopsis", value:"The remote Ubuntu host is missing a security-related patch." ); script_set_attribute( attribute:"description", value: "It was discovered that LibreOffice incorrectly handled certain document files. If a user were tricked into opening a specially crafted document, a remote attacker could cause LibreOffice to crash, and possibly execute arbitrary code. (CVE-2018-10119, CVE-2018-10120, CVE-2018-11790) It was discovered that LibreOffice incorrectly handled embedded SMB connections in document files. If a user were tricked in to opening a specially crafted document, a remote attacker could possibly exploit this to obtain sensitive information. (CVE-2018-10583) Alex Infuhr discovered that LibreOffice incorrectly handled embedded scripts in document files. If a user were tricked into opening a specially crafted document, a remote attacker could possibly execute arbitrary code. (CVE-2018-16858). Note that Tenable Network Security has extracted the preceding description block directly from the Ubuntu security advisory. Tenable has attempted to automatically clean and format it as much as possible without introducing additional issues." ); script_set_attribute( attribute:"see_also", value:"https://usn.ubuntu.com/3883-1/" ); script_set_attribute( attribute:"solution", value:"Update the affected libreoffice-core package." ); script_set_cvss_base_vector("CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P"); script_set_cvss_temporal_vector("CVSS2#E:H/RL:OF/RC:C"); script_set_cvss3_base_vector("CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"); script_set_cvss3_temporal_vector("CVSS:3.0/E:H/RL:O/RC:C"); script_set_attribute(attribute:"exploitability_ease", value:"Exploits are available"); script_set_attribute(attribute:"exploit_available", value:"true"); script_set_attribute(attribute:"exploited_by_malware", value:"true"); script_set_attribute(attribute:"metasploit_name", value:'LibreOffice Macro Code Execution'); script_set_attribute(attribute:"exploit_framework_metasploit", value:"true"); script_set_attribute(attribute:"plugin_type", value:"local"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:canonical:ubuntu_linux:libreoffice-core"); script_set_attribute(attribute:"cpe", value:"cpe:/o:canonical:ubuntu_linux:14.04"); script_set_attribute(attribute:"cpe", value:"cpe:/o:canonical:ubuntu_linux:16.04"); script_set_attribute(attribute:"vuln_publication_date", value:"2018/04/16"); script_set_attribute(attribute:"patch_publication_date", value:"2019/02/06"); script_set_attribute(attribute:"plugin_publication_date", value:"2019/02/07"); script_set_attribute(attribute:"generated_plugin", value:"current"); script_end_attributes(); script_category(ACT_GATHER_INFO); script_copyright(english:"Ubuntu Security Notice (C) 2019 Canonical, Inc. / NASL script (C) 2019 and is owned by Tenable, Inc. or an Affiliate thereof."); script_family(english:"Ubuntu Local Security Checks"); script_dependencies("ssh_get_info.nasl"); script_require_keys("Host/cpu", "Host/Ubuntu", "Host/Ubuntu/release", "Host/Debian/dpkg-l"); exit(0); } include("audit.inc"); include("ubuntu.inc"); include("misc_func.inc"); if ( ! get_kb_item("Host/local_checks_enabled") ) audit(AUDIT_LOCAL_CHECKS_NOT_ENABLED); release = get_kb_item("Host/Ubuntu/release"); if ( isnull(release) ) audit(AUDIT_OS_NOT, "Ubuntu"); release = chomp(release); if (! preg(pattern:"^(14\.04|16\.04)$", string:release)) audit(AUDIT_OS_NOT, "Ubuntu 14.04 / 16.04", "Ubuntu " + release); if ( ! get_kb_item("Host/Debian/dpkg-l") ) audit(AUDIT_PACKAGE_LIST_MISSING); cpu = get_kb_item("Host/cpu"); if (isnull(cpu)) audit(AUDIT_UNKNOWN_ARCH); if ("x86_64" >!< cpu && cpu !~ "^i[3-6]86$") audit(AUDIT_LOCAL_CHECKS_NOT_IMPLEMENTED, "Ubuntu", cpu); flag = 0; if (ubuntu_check(osver:"14.04", pkgname:"libreoffice-core", pkgver:"1:4.2.8-0ubuntu5.5")) flag++; if (ubuntu_check(osver:"16.04", pkgname:"libreoffice-core", pkgver:"1:5.1.6~rc2-0ubuntu1~xenial6")) flag++; if (flag) { security_report_v4( port : 0, severity : SECURITY_HOLE, extra : ubuntu_report_get() ); exit(0); } else { tested = ubuntu_pkg_tests_get(); if (tested) audit(AUDIT_PACKAGE_NOT_AFFECTED, tested); else audit(AUDIT_PACKAGE_NOT_INSTALLED, "libreoffice-core"); }
NASL family Fedora Local Security Checks NASL id FEDORA_2018-E87EB1AE68.NASL description - CVE-2018-10119 Use after free in sdstor/stgstrms.cxx - CVE-2018-10120 Out of bounds write in filter/ww8/ww8toolbar.cxx Note that Tenable Network Security has extracted the preceding description block directly from the Fedora update system website. Tenable has attempted to automatically clean and format it as much as possible without introducing additional issues. last seen 2020-06-05 modified 2018-04-30 plugin id 109423 published 2018-04-30 reporter This script is Copyright (C) 2018-2020 and is owned by Tenable, Inc. or an Affiliate thereof. source https://www.tenable.com/plugins/nessus/109423 title Fedora 26 : 1:libreoffice (2018-e87eb1ae68) code #%NASL_MIN_LEVEL 80502 # # (C) Tenable Network Security, Inc. # # The descriptive text and package checks in this plugin were # extracted from Fedora Security Advisory FEDORA-2018-e87eb1ae68. # include("compat.inc"); if (description) { script_id(109423); script_version("1.5"); script_set_attribute(attribute:"plugin_modification_date", value:"2020/06/04"); script_cve_id("CVE-2018-10119", "CVE-2018-10120"); script_xref(name:"FEDORA", value:"2018-e87eb1ae68"); script_name(english:"Fedora 26 : 1:libreoffice (2018-e87eb1ae68)"); script_summary(english:"Checks rpm output for the updated package."); script_set_attribute( attribute:"synopsis", value:"The remote Fedora host is missing a security update." ); script_set_attribute( attribute:"description", value: " - CVE-2018-10119 Use after free in sdstor/stgstrms.cxx - CVE-2018-10120 Out of bounds write in filter/ww8/ww8toolbar.cxx Note that Tenable Network Security has extracted the preceding description block directly from the Fedora update system website. Tenable has attempted to automatically clean and format it as much as possible without introducing additional issues." ); script_set_attribute( attribute:"see_also", value:"https://bodhi.fedoraproject.org/updates/FEDORA-2018-e87eb1ae68" ); script_set_attribute( attribute:"solution", value:"Update the affected 1:libreoffice package." ); script_set_cvss_base_vector("CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P"); script_set_cvss3_base_vector("CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"); script_set_attribute(attribute:"plugin_type", value:"local"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:fedoraproject:fedora:1:libreoffice"); script_set_attribute(attribute:"cpe", value:"cpe:/o:fedoraproject:fedora:26"); script_set_attribute(attribute:"vuln_publication_date", value:"2018/04/16"); script_set_attribute(attribute:"patch_publication_date", value:"2018/04/29"); script_set_attribute(attribute:"plugin_publication_date", value:"2018/04/30"); script_set_attribute(attribute:"generated_plugin", value:"current"); script_end_attributes(); script_category(ACT_GATHER_INFO); script_copyright(english:"This script is Copyright (C) 2018-2020 and is owned by Tenable, Inc. or an Affiliate thereof."); script_family(english:"Fedora Local Security Checks"); script_dependencies("ssh_get_info.nasl"); script_require_keys("Host/local_checks_enabled", "Host/RedHat/release", "Host/RedHat/rpm-list"); exit(0); } include("audit.inc"); include("global_settings.inc"); include("rpm.inc"); if (!get_kb_item("Host/local_checks_enabled")) audit(AUDIT_LOCAL_CHECKS_NOT_ENABLED); release = get_kb_item("Host/RedHat/release"); if (isnull(release) || "Fedora" >!< release) audit(AUDIT_OS_NOT, "Fedora"); os_ver = pregmatch(pattern: "Fedora.*release ([0-9]+)", string:release); if (isnull(os_ver)) audit(AUDIT_UNKNOWN_APP_VER, "Fedora"); os_ver = os_ver[1]; if (! preg(pattern:"^26([^0-9]|$)", string:os_ver)) audit(AUDIT_OS_NOT, "Fedora 26", "Fedora " + os_ver); if (!get_kb_item("Host/RedHat/rpm-list")) audit(AUDIT_PACKAGE_LIST_MISSING); cpu = get_kb_item("Host/cpu"); if (isnull(cpu)) audit(AUDIT_UNKNOWN_ARCH); if ("x86_64" >!< cpu && cpu !~ "^i[3-6]86$") audit(AUDIT_LOCAL_CHECKS_NOT_IMPLEMENTED, "Fedora", cpu); flag = 0; if (rpm_check(release:"FC26", reference:"libreoffice-5.3.7.2-9.fc26", epoch:"1")) flag++; if (flag) { security_report_v4( port : 0, severity : SECURITY_WARNING, extra : rpm_report_get() ); exit(0); } else { tested = pkg_tests_get(); if (tested) audit(AUDIT_PACKAGE_NOT_AFFECTED, tested); else audit(AUDIT_PACKAGE_NOT_INSTALLED, "1:libreoffice"); }
NASL family Debian Local Security Checks NASL id DEBIAN_DLA-1356.NASL description Fuzzing by the OSS-Fuzz project found two memory safety issues in LibreOffice, which could result in an application crash or possibly other unspecified impact. For Debian 7 last seen 2020-03-17 modified 2018-04-20 plugin id 109188 published 2018-04-20 reporter This script is Copyright (C) 2018-2020 and is owned by Tenable, Inc. or an Affiliate thereof. source https://www.tenable.com/plugins/nessus/109188 title Debian DLA-1356-1 : libreoffice security update code #%NASL_MIN_LEVEL 80502 # # (C) Tenable Network Security, Inc. # # The descriptive text and package checks in this plugin were # extracted from Debian Security Advisory DLA-1356-1. The text # itself is copyright (C) Software in the Public Interest, Inc. # include("compat.inc"); if (description) { script_id(109188); script_version("1.4"); script_set_attribute(attribute:"plugin_modification_date", value:"2020/03/12"); script_cve_id("CVE-2018-10119", "CVE-2018-10120"); script_name(english:"Debian DLA-1356-1 : libreoffice security update"); script_summary(english:"Checks dpkg output for the updated packages."); script_set_attribute( attribute:"synopsis", value:"The remote Debian host is missing a security update." ); script_set_attribute( attribute:"description", value: "Fuzzing by the OSS-Fuzz project found two memory safety issues in LibreOffice, which could result in an application crash or possibly other unspecified impact. For Debian 7 'Wheezy', these problems have been fixed in version 1:3.5.4+dfsg2-0+deb7u11. We recommend that you upgrade your libreoffice packages. NOTE: Tenable Network Security has extracted the preceding description block directly from the DLA security advisory. Tenable has attempted to automatically clean and format it as much as possible without introducing additional issues." ); script_set_attribute( attribute:"see_also", value:"https://lists.debian.org/debian-lts-announce/2018/04/msg00021.html" ); script_set_attribute( attribute:"see_also", value:"https://packages.debian.org/source/wheezy/libreoffice" ); script_set_attribute(attribute:"solution", value:"Upgrade the affected packages."); script_set_cvss_base_vector("CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P"); script_set_cvss3_base_vector("CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"); script_set_attribute(attribute:"plugin_type", value:"local"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:debian:debian_linux:fonts-opensymbol"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:debian:debian_linux:libreoffice"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:debian:debian_linux:libreoffice-base"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:debian:debian_linux:libreoffice-base-core"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:debian:debian_linux:libreoffice-calc"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:debian:debian_linux:libreoffice-common"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:debian:debian_linux:libreoffice-core"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:debian:debian_linux:libreoffice-dbg"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:debian:debian_linux:libreoffice-dev"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:debian:debian_linux:libreoffice-dev-doc"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:debian:debian_linux:libreoffice-draw"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:debian:debian_linux:libreoffice-emailmerge"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:debian:debian_linux:libreoffice-evolution"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:debian:debian_linux:libreoffice-filter-binfilter"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:debian:debian_linux:libreoffice-filter-mobiledev"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:debian:debian_linux:libreoffice-gcj"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:debian:debian_linux:libreoffice-gnome"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:debian:debian_linux:libreoffice-gtk"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:debian:debian_linux:libreoffice-gtk3"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:debian:debian_linux:libreoffice-help-ca"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:debian:debian_linux:libreoffice-help-cs"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:debian:debian_linux:libreoffice-help-da"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:debian:debian_linux:libreoffice-help-de"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:debian:debian_linux:libreoffice-help-dz"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:debian:debian_linux:libreoffice-help-el"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:debian:debian_linux:libreoffice-help-en-gb"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:debian:debian_linux:libreoffice-help-en-us"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:debian:debian_linux:libreoffice-help-es"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:debian:debian_linux:libreoffice-help-et"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:debian:debian_linux:libreoffice-help-eu"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:debian:debian_linux:libreoffice-help-fi"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:debian:debian_linux:libreoffice-help-fr"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:debian:debian_linux:libreoffice-help-gl"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:debian:debian_linux:libreoffice-help-hi"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:debian:debian_linux:libreoffice-help-hu"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:debian:debian_linux:libreoffice-help-it"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:debian:debian_linux:libreoffice-help-ja"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:debian:debian_linux:libreoffice-help-km"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:debian:debian_linux:libreoffice-help-ko"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:debian:debian_linux:libreoffice-help-nl"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:debian:debian_linux:libreoffice-help-om"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:debian:debian_linux:libreoffice-help-pl"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:debian:debian_linux:libreoffice-help-pt"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:debian:debian_linux:libreoffice-help-pt-br"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:debian:debian_linux:libreoffice-help-ru"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:debian:debian_linux:libreoffice-help-sk"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:debian:debian_linux:libreoffice-help-sl"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:debian:debian_linux:libreoffice-help-sv"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:debian:debian_linux:libreoffice-help-zh-cn"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:debian:debian_linux:libreoffice-help-zh-tw"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:debian:debian_linux:libreoffice-impress"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:debian:debian_linux:libreoffice-java-common"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:debian:debian_linux:libreoffice-kde"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:debian:debian_linux:libreoffice-l10n-af"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:debian:debian_linux:libreoffice-l10n-ar"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:debian:debian_linux:libreoffice-l10n-as"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:debian:debian_linux:libreoffice-l10n-ast"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:debian:debian_linux:libreoffice-l10n-be"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:debian:debian_linux:libreoffice-l10n-bg"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:debian:debian_linux:libreoffice-l10n-bn"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:debian:debian_linux:libreoffice-l10n-br"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:debian:debian_linux:libreoffice-l10n-bs"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:debian:debian_linux:libreoffice-l10n-ca"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:debian:debian_linux:libreoffice-l10n-cs"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:debian:debian_linux:libreoffice-l10n-cy"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:debian:debian_linux:libreoffice-l10n-da"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:debian:debian_linux:libreoffice-l10n-de"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:debian:debian_linux:libreoffice-l10n-dz"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:debian:debian_linux:libreoffice-l10n-el"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:debian:debian_linux:libreoffice-l10n-en-gb"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:debian:debian_linux:libreoffice-l10n-en-za"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:debian:debian_linux:libreoffice-l10n-eo"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:debian:debian_linux:libreoffice-l10n-es"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:debian:debian_linux:libreoffice-l10n-et"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:debian:debian_linux:libreoffice-l10n-eu"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:debian:debian_linux:libreoffice-l10n-fa"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:debian:debian_linux:libreoffice-l10n-fi"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:debian:debian_linux:libreoffice-l10n-fr"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:debian:debian_linux:libreoffice-l10n-ga"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:debian:debian_linux:libreoffice-l10n-gl"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:debian:debian_linux:libreoffice-l10n-gu"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:debian:debian_linux:libreoffice-l10n-he"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:debian:debian_linux:libreoffice-l10n-hi"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:debian:debian_linux:libreoffice-l10n-hr"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:debian:debian_linux:libreoffice-l10n-hu"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:debian:debian_linux:libreoffice-l10n-id"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:debian:debian_linux:libreoffice-l10n-in"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:debian:debian_linux:libreoffice-l10n-is"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:debian:debian_linux:libreoffice-l10n-it"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:debian:debian_linux:libreoffice-l10n-ja"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:debian:debian_linux:libreoffice-l10n-ka"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:debian:debian_linux:libreoffice-l10n-km"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:debian:debian_linux:libreoffice-l10n-ko"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:debian:debian_linux:libreoffice-l10n-ku"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:debian:debian_linux:libreoffice-l10n-lt"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:debian:debian_linux:libreoffice-l10n-lv"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:debian:debian_linux:libreoffice-l10n-mk"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:debian:debian_linux:libreoffice-l10n-ml"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:debian:debian_linux:libreoffice-l10n-mn"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:debian:debian_linux:libreoffice-l10n-mr"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:debian:debian_linux:libreoffice-l10n-nb"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:debian:debian_linux:libreoffice-l10n-ne"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:debian:debian_linux:libreoffice-l10n-nl"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:debian:debian_linux:libreoffice-l10n-nn"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:debian:debian_linux:libreoffice-l10n-nr"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:debian:debian_linux:libreoffice-l10n-nso"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:debian:debian_linux:libreoffice-l10n-oc"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:debian:debian_linux:libreoffice-l10n-om"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:debian:debian_linux:libreoffice-l10n-or"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:debian:debian_linux:libreoffice-l10n-pa-in"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:debian:debian_linux:libreoffice-l10n-pl"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:debian:debian_linux:libreoffice-l10n-pt"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:debian:debian_linux:libreoffice-l10n-pt-br"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:debian:debian_linux:libreoffice-l10n-ro"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:debian:debian_linux:libreoffice-l10n-ru"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:debian:debian_linux:libreoffice-l10n-rw"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:debian:debian_linux:libreoffice-l10n-si"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:debian:debian_linux:libreoffice-l10n-sk"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:debian:debian_linux:libreoffice-l10n-sl"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:debian:debian_linux:libreoffice-l10n-sr"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:debian:debian_linux:libreoffice-l10n-ss"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:debian:debian_linux:libreoffice-l10n-st"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:debian:debian_linux:libreoffice-l10n-sv"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:debian:debian_linux:libreoffice-l10n-ta"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:debian:debian_linux:libreoffice-l10n-te"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:debian:debian_linux:libreoffice-l10n-tg"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:debian:debian_linux:libreoffice-l10n-th"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:debian:debian_linux:libreoffice-l10n-tn"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:debian:debian_linux:libreoffice-l10n-tr"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:debian:debian_linux:libreoffice-l10n-ts"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:debian:debian_linux:libreoffice-l10n-ug"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:debian:debian_linux:libreoffice-l10n-uk"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:debian:debian_linux:libreoffice-l10n-uz"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:debian:debian_linux:libreoffice-l10n-ve"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:debian:debian_linux:libreoffice-l10n-vi"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:debian:debian_linux:libreoffice-l10n-xh"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:debian:debian_linux:libreoffice-l10n-za"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:debian:debian_linux:libreoffice-l10n-zh-cn"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:debian:debian_linux:libreoffice-l10n-zh-tw"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:debian:debian_linux:libreoffice-l10n-zu"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:debian:debian_linux:libreoffice-math"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:debian:debian_linux:libreoffice-mysql-connector"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:debian:debian_linux:libreoffice-officebean"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:debian:debian_linux:libreoffice-ogltrans"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:debian:debian_linux:libreoffice-pdfimport"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:debian:debian_linux:libreoffice-presentation-minimizer"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:debian:debian_linux:libreoffice-presenter-console"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:debian:debian_linux:libreoffice-report-builder"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:debian:debian_linux:libreoffice-report-builder-bin"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:debian:debian_linux:libreoffice-script-provider-bsh"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:debian:debian_linux:libreoffice-script-provider-js"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:debian:debian_linux:libreoffice-script-provider-python"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:debian:debian_linux:libreoffice-sdbc-postgresql"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:debian:debian_linux:libreoffice-style-crystal"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:debian:debian_linux:libreoffice-style-galaxy"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:debian:debian_linux:libreoffice-style-hicontrast"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:debian:debian_linux:libreoffice-style-oxygen"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:debian:debian_linux:libreoffice-style-tango"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:debian:debian_linux:libreoffice-wiki-publisher"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:debian:debian_linux:libreoffice-writer"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:debian:debian_linux:openoffice.org-dtd-officedocument1.0"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:debian:debian_linux:python-uno"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:debian:debian_linux:python3-uno"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:debian:debian_linux:ttf-opensymbol"); script_set_attribute(attribute:"cpe", value:"cpe:/o:debian:debian_linux:7.0"); script_set_attribute(attribute:"patch_publication_date", value:"2018/04/19"); script_set_attribute(attribute:"plugin_publication_date", value:"2018/04/20"); script_end_attributes(); script_category(ACT_GATHER_INFO); script_copyright(english:"This script is Copyright (C) 2018-2020 and is owned by Tenable, Inc. or an Affiliate thereof."); script_family(english:"Debian Local Security Checks"); script_dependencies("ssh_get_info.nasl"); script_require_keys("Host/local_checks_enabled", "Host/Debian/release", "Host/Debian/dpkg-l"); exit(0); } include("audit.inc"); include("debian_package.inc"); if (!get_kb_item("Host/local_checks_enabled")) audit(AUDIT_LOCAL_CHECKS_NOT_ENABLED); if (!get_kb_item("Host/Debian/release")) audit(AUDIT_OS_NOT, "Debian"); if (!get_kb_item("Host/Debian/dpkg-l")) audit(AUDIT_PACKAGE_LIST_MISSING); flag = 0; if (deb_check(release:"7.0", prefix:"fonts-opensymbol", reference:"1:3.5.4+dfsg2-0+deb7u11")) flag++; if (deb_check(release:"7.0", prefix:"libreoffice", reference:"1:3.5.4+dfsg2-0+deb7u11")) flag++; if (deb_check(release:"7.0", prefix:"libreoffice-base", reference:"1:3.5.4+dfsg2-0+deb7u11")) flag++; if (deb_check(release:"7.0", prefix:"libreoffice-base-core", reference:"1:3.5.4+dfsg2-0+deb7u11")) flag++; if (deb_check(release:"7.0", prefix:"libreoffice-calc", reference:"1:3.5.4+dfsg2-0+deb7u11")) flag++; if (deb_check(release:"7.0", prefix:"libreoffice-common", reference:"1:3.5.4+dfsg2-0+deb7u11")) flag++; if (deb_check(release:"7.0", prefix:"libreoffice-core", reference:"1:3.5.4+dfsg2-0+deb7u11")) flag++; if (deb_check(release:"7.0", prefix:"libreoffice-dbg", reference:"1:3.5.4+dfsg2-0+deb7u11")) flag++; if (deb_check(release:"7.0", prefix:"libreoffice-dev", reference:"1:3.5.4+dfsg2-0+deb7u11")) flag++; if (deb_check(release:"7.0", prefix:"libreoffice-dev-doc", reference:"1:3.5.4+dfsg2-0+deb7u11")) flag++; if (deb_check(release:"7.0", prefix:"libreoffice-draw", reference:"1:3.5.4+dfsg2-0+deb7u11")) flag++; if (deb_check(release:"7.0", prefix:"libreoffice-emailmerge", reference:"1:3.5.4+dfsg2-0+deb7u11")) flag++; if (deb_check(release:"7.0", prefix:"libreoffice-evolution", reference:"1:3.5.4+dfsg2-0+deb7u11")) flag++; if (deb_check(release:"7.0", prefix:"libreoffice-filter-binfilter", reference:"1:3.5.4+dfsg2-0+deb7u11")) flag++; if (deb_check(release:"7.0", prefix:"libreoffice-filter-mobiledev", reference:"1:3.5.4+dfsg2-0+deb7u11")) flag++; if (deb_check(release:"7.0", prefix:"libreoffice-gcj", reference:"1:3.5.4+dfsg2-0+deb7u11")) flag++; if (deb_check(release:"7.0", prefix:"libreoffice-gnome", reference:"1:3.5.4+dfsg2-0+deb7u11")) flag++; if (deb_check(release:"7.0", prefix:"libreoffice-gtk", reference:"1:3.5.4+dfsg2-0+deb7u11")) flag++; if (deb_check(release:"7.0", prefix:"libreoffice-gtk3", reference:"1:3.5.4+dfsg2-0+deb7u11")) flag++; if (deb_check(release:"7.0", prefix:"libreoffice-help-ca", reference:"1:3.5.4+dfsg2-0+deb7u11")) flag++; if (deb_check(release:"7.0", prefix:"libreoffice-help-cs", reference:"1:3.5.4+dfsg2-0+deb7u11")) flag++; if (deb_check(release:"7.0", prefix:"libreoffice-help-da", reference:"1:3.5.4+dfsg2-0+deb7u11")) flag++; if (deb_check(release:"7.0", prefix:"libreoffice-help-de", reference:"1:3.5.4+dfsg2-0+deb7u11")) flag++; if (deb_check(release:"7.0", prefix:"libreoffice-help-dz", reference:"1:3.5.4+dfsg2-0+deb7u11")) flag++; if (deb_check(release:"7.0", prefix:"libreoffice-help-el", reference:"1:3.5.4+dfsg2-0+deb7u11")) flag++; if (deb_check(release:"7.0", prefix:"libreoffice-help-en-gb", reference:"1:3.5.4+dfsg2-0+deb7u11")) flag++; if (deb_check(release:"7.0", prefix:"libreoffice-help-en-us", reference:"1:3.5.4+dfsg2-0+deb7u11")) flag++; if (deb_check(release:"7.0", prefix:"libreoffice-help-es", reference:"1:3.5.4+dfsg2-0+deb7u11")) flag++; if (deb_check(release:"7.0", prefix:"libreoffice-help-et", reference:"1:3.5.4+dfsg2-0+deb7u11")) flag++; if (deb_check(release:"7.0", prefix:"libreoffice-help-eu", reference:"1:3.5.4+dfsg2-0+deb7u11")) flag++; if (deb_check(release:"7.0", prefix:"libreoffice-help-fi", reference:"1:3.5.4+dfsg2-0+deb7u11")) flag++; if (deb_check(release:"7.0", prefix:"libreoffice-help-fr", reference:"1:3.5.4+dfsg2-0+deb7u11")) flag++; if (deb_check(release:"7.0", prefix:"libreoffice-help-gl", reference:"1:3.5.4+dfsg2-0+deb7u11")) flag++; if (deb_check(release:"7.0", prefix:"libreoffice-help-hi", reference:"1:3.5.4+dfsg2-0+deb7u11")) flag++; if (deb_check(release:"7.0", prefix:"libreoffice-help-hu", reference:"1:3.5.4+dfsg2-0+deb7u11")) flag++; if (deb_check(release:"7.0", prefix:"libreoffice-help-it", reference:"1:3.5.4+dfsg2-0+deb7u11")) flag++; if (deb_check(release:"7.0", prefix:"libreoffice-help-ja", reference:"1:3.5.4+dfsg2-0+deb7u11")) flag++; if (deb_check(release:"7.0", prefix:"libreoffice-help-km", reference:"1:3.5.4+dfsg2-0+deb7u11")) flag++; if (deb_check(release:"7.0", prefix:"libreoffice-help-ko", reference:"1:3.5.4+dfsg2-0+deb7u11")) flag++; if (deb_check(release:"7.0", prefix:"libreoffice-help-nl", reference:"1:3.5.4+dfsg2-0+deb7u11")) flag++; if (deb_check(release:"7.0", prefix:"libreoffice-help-om", reference:"1:3.5.4+dfsg2-0+deb7u11")) flag++; if (deb_check(release:"7.0", prefix:"libreoffice-help-pl", reference:"1:3.5.4+dfsg2-0+deb7u11")) flag++; if (deb_check(release:"7.0", prefix:"libreoffice-help-pt", reference:"1:3.5.4+dfsg2-0+deb7u11")) flag++; if (deb_check(release:"7.0", prefix:"libreoffice-help-pt-br", reference:"1:3.5.4+dfsg2-0+deb7u11")) flag++; if (deb_check(release:"7.0", prefix:"libreoffice-help-ru", reference:"1:3.5.4+dfsg2-0+deb7u11")) flag++; if (deb_check(release:"7.0", prefix:"libreoffice-help-sk", reference:"1:3.5.4+dfsg2-0+deb7u11")) flag++; if (deb_check(release:"7.0", prefix:"libreoffice-help-sl", reference:"1:3.5.4+dfsg2-0+deb7u11")) flag++; if (deb_check(release:"7.0", prefix:"libreoffice-help-sv", reference:"1:3.5.4+dfsg2-0+deb7u11")) flag++; if (deb_check(release:"7.0", prefix:"libreoffice-help-zh-cn", reference:"1:3.5.4+dfsg2-0+deb7u11")) flag++; if (deb_check(release:"7.0", prefix:"libreoffice-help-zh-tw", reference:"1:3.5.4+dfsg2-0+deb7u11")) flag++; if (deb_check(release:"7.0", prefix:"libreoffice-impress", reference:"1:3.5.4+dfsg2-0+deb7u11")) flag++; if (deb_check(release:"7.0", prefix:"libreoffice-java-common", reference:"1:3.5.4+dfsg2-0+deb7u11")) flag++; if (deb_check(release:"7.0", prefix:"libreoffice-kde", reference:"1:3.5.4+dfsg2-0+deb7u11")) flag++; if (deb_check(release:"7.0", prefix:"libreoffice-l10n-af", reference:"1:3.5.4+dfsg2-0+deb7u11")) flag++; if (deb_check(release:"7.0", prefix:"libreoffice-l10n-ar", reference:"1:3.5.4+dfsg2-0+deb7u11")) flag++; if (deb_check(release:"7.0", prefix:"libreoffice-l10n-as", reference:"1:3.5.4+dfsg2-0+deb7u11")) flag++; if (deb_check(release:"7.0", prefix:"libreoffice-l10n-ast", reference:"1:3.5.4+dfsg2-0+deb7u11")) flag++; if (deb_check(release:"7.0", prefix:"libreoffice-l10n-be", reference:"1:3.5.4+dfsg2-0+deb7u11")) flag++; if (deb_check(release:"7.0", prefix:"libreoffice-l10n-bg", reference:"1:3.5.4+dfsg2-0+deb7u11")) flag++; if (deb_check(release:"7.0", prefix:"libreoffice-l10n-bn", reference:"1:3.5.4+dfsg2-0+deb7u11")) flag++; if (deb_check(release:"7.0", prefix:"libreoffice-l10n-br", reference:"1:3.5.4+dfsg2-0+deb7u11")) flag++; if (deb_check(release:"7.0", prefix:"libreoffice-l10n-bs", reference:"1:3.5.4+dfsg2-0+deb7u11")) flag++; if (deb_check(release:"7.0", prefix:"libreoffice-l10n-ca", reference:"1:3.5.4+dfsg2-0+deb7u11")) flag++; if (deb_check(release:"7.0", prefix:"libreoffice-l10n-cs", reference:"1:3.5.4+dfsg2-0+deb7u11")) flag++; if (deb_check(release:"7.0", prefix:"libreoffice-l10n-cy", reference:"1:3.5.4+dfsg2-0+deb7u11")) flag++; if (deb_check(release:"7.0", prefix:"libreoffice-l10n-da", reference:"1:3.5.4+dfsg2-0+deb7u11")) flag++; if (deb_check(release:"7.0", prefix:"libreoffice-l10n-de", reference:"1:3.5.4+dfsg2-0+deb7u11")) flag++; if (deb_check(release:"7.0", prefix:"libreoffice-l10n-dz", reference:"1:3.5.4+dfsg2-0+deb7u11")) flag++; if (deb_check(release:"7.0", prefix:"libreoffice-l10n-el", reference:"1:3.5.4+dfsg2-0+deb7u11")) flag++; if (deb_check(release:"7.0", prefix:"libreoffice-l10n-en-gb", reference:"1:3.5.4+dfsg2-0+deb7u11")) flag++; if (deb_check(release:"7.0", prefix:"libreoffice-l10n-en-za", reference:"1:3.5.4+dfsg2-0+deb7u11")) flag++; if (deb_check(release:"7.0", prefix:"libreoffice-l10n-eo", reference:"1:3.5.4+dfsg2-0+deb7u11")) flag++; if (deb_check(release:"7.0", prefix:"libreoffice-l10n-es", reference:"1:3.5.4+dfsg2-0+deb7u11")) flag++; if (deb_check(release:"7.0", prefix:"libreoffice-l10n-et", reference:"1:3.5.4+dfsg2-0+deb7u11")) flag++; if (deb_check(release:"7.0", prefix:"libreoffice-l10n-eu", reference:"1:3.5.4+dfsg2-0+deb7u11")) flag++; if (deb_check(release:"7.0", prefix:"libreoffice-l10n-fa", reference:"1:3.5.4+dfsg2-0+deb7u11")) flag++; if (deb_check(release:"7.0", prefix:"libreoffice-l10n-fi", reference:"1:3.5.4+dfsg2-0+deb7u11")) flag++; if (deb_check(release:"7.0", prefix:"libreoffice-l10n-fr", reference:"1:3.5.4+dfsg2-0+deb7u11")) flag++; if (deb_check(release:"7.0", prefix:"libreoffice-l10n-ga", reference:"1:3.5.4+dfsg2-0+deb7u11")) flag++; if (deb_check(release:"7.0", prefix:"libreoffice-l10n-gl", reference:"1:3.5.4+dfsg2-0+deb7u11")) flag++; if (deb_check(release:"7.0", prefix:"libreoffice-l10n-gu", reference:"1:3.5.4+dfsg2-0+deb7u11")) flag++; if (deb_check(release:"7.0", prefix:"libreoffice-l10n-he", reference:"1:3.5.4+dfsg2-0+deb7u11")) flag++; if (deb_check(release:"7.0", prefix:"libreoffice-l10n-hi", reference:"1:3.5.4+dfsg2-0+deb7u11")) flag++; if (deb_check(release:"7.0", prefix:"libreoffice-l10n-hr", reference:"1:3.5.4+dfsg2-0+deb7u11")) flag++; if (deb_check(release:"7.0", prefix:"libreoffice-l10n-hu", reference:"1:3.5.4+dfsg2-0+deb7u11")) flag++; if (deb_check(release:"7.0", prefix:"libreoffice-l10n-id", reference:"1:3.5.4+dfsg2-0+deb7u11")) flag++; if (deb_check(release:"7.0", prefix:"libreoffice-l10n-in", reference:"1:3.5.4+dfsg2-0+deb7u11")) flag++; if (deb_check(release:"7.0", prefix:"libreoffice-l10n-is", reference:"1:3.5.4+dfsg2-0+deb7u11")) flag++; if (deb_check(release:"7.0", prefix:"libreoffice-l10n-it", reference:"1:3.5.4+dfsg2-0+deb7u11")) flag++; if (deb_check(release:"7.0", prefix:"libreoffice-l10n-ja", reference:"1:3.5.4+dfsg2-0+deb7u11")) flag++; if (deb_check(release:"7.0", prefix:"libreoffice-l10n-ka", reference:"1:3.5.4+dfsg2-0+deb7u11")) flag++; if (deb_check(release:"7.0", prefix:"libreoffice-l10n-km", reference:"1:3.5.4+dfsg2-0+deb7u11")) flag++; if (deb_check(release:"7.0", prefix:"libreoffice-l10n-ko", reference:"1:3.5.4+dfsg2-0+deb7u11")) flag++; if (deb_check(release:"7.0", prefix:"libreoffice-l10n-ku", reference:"1:3.5.4+dfsg2-0+deb7u11")) flag++; if (deb_check(release:"7.0", prefix:"libreoffice-l10n-lt", reference:"1:3.5.4+dfsg2-0+deb7u11")) flag++; if (deb_check(release:"7.0", prefix:"libreoffice-l10n-lv", reference:"1:3.5.4+dfsg2-0+deb7u11")) flag++; if (deb_check(release:"7.0", prefix:"libreoffice-l10n-mk", reference:"1:3.5.4+dfsg2-0+deb7u11")) flag++; if (deb_check(release:"7.0", prefix:"libreoffice-l10n-ml", reference:"1:3.5.4+dfsg2-0+deb7u11")) flag++; if (deb_check(release:"7.0", prefix:"libreoffice-l10n-mn", reference:"1:3.5.4+dfsg2-0+deb7u11")) flag++; if (deb_check(release:"7.0", prefix:"libreoffice-l10n-mr", reference:"1:3.5.4+dfsg2-0+deb7u11")) flag++; if (deb_check(release:"7.0", prefix:"libreoffice-l10n-nb", reference:"1:3.5.4+dfsg2-0+deb7u11")) flag++; if (deb_check(release:"7.0", prefix:"libreoffice-l10n-ne", reference:"1:3.5.4+dfsg2-0+deb7u11")) flag++; if (deb_check(release:"7.0", prefix:"libreoffice-l10n-nl", reference:"1:3.5.4+dfsg2-0+deb7u11")) flag++; if (deb_check(release:"7.0", prefix:"libreoffice-l10n-nn", reference:"1:3.5.4+dfsg2-0+deb7u11")) flag++; if (deb_check(release:"7.0", prefix:"libreoffice-l10n-nr", reference:"1:3.5.4+dfsg2-0+deb7u11")) flag++; if (deb_check(release:"7.0", prefix:"libreoffice-l10n-nso", reference:"1:3.5.4+dfsg2-0+deb7u11")) flag++; if (deb_check(release:"7.0", prefix:"libreoffice-l10n-oc", reference:"1:3.5.4+dfsg2-0+deb7u11")) flag++; if (deb_check(release:"7.0", prefix:"libreoffice-l10n-om", reference:"1:3.5.4+dfsg2-0+deb7u11")) flag++; if (deb_check(release:"7.0", prefix:"libreoffice-l10n-or", reference:"1:3.5.4+dfsg2-0+deb7u11")) flag++; if (deb_check(release:"7.0", prefix:"libreoffice-l10n-pa-in", reference:"1:3.5.4+dfsg2-0+deb7u11")) flag++; if (deb_check(release:"7.0", prefix:"libreoffice-l10n-pl", reference:"1:3.5.4+dfsg2-0+deb7u11")) flag++; if (deb_check(release:"7.0", prefix:"libreoffice-l10n-pt", reference:"1:3.5.4+dfsg2-0+deb7u11")) flag++; if (deb_check(release:"7.0", prefix:"libreoffice-l10n-pt-br", reference:"1:3.5.4+dfsg2-0+deb7u11")) flag++; if (deb_check(release:"7.0", prefix:"libreoffice-l10n-ro", reference:"1:3.5.4+dfsg2-0+deb7u11")) flag++; if (deb_check(release:"7.0", prefix:"libreoffice-l10n-ru", reference:"1:3.5.4+dfsg2-0+deb7u11")) flag++; if (deb_check(release:"7.0", prefix:"libreoffice-l10n-rw", reference:"1:3.5.4+dfsg2-0+deb7u11")) flag++; if (deb_check(release:"7.0", prefix:"libreoffice-l10n-si", reference:"1:3.5.4+dfsg2-0+deb7u11")) flag++; if (deb_check(release:"7.0", prefix:"libreoffice-l10n-sk", reference:"1:3.5.4+dfsg2-0+deb7u11")) flag++; if (deb_check(release:"7.0", prefix:"libreoffice-l10n-sl", reference:"1:3.5.4+dfsg2-0+deb7u11")) flag++; if (deb_check(release:"7.0", prefix:"libreoffice-l10n-sr", reference:"1:3.5.4+dfsg2-0+deb7u11")) flag++; if (deb_check(release:"7.0", prefix:"libreoffice-l10n-ss", reference:"1:3.5.4+dfsg2-0+deb7u11")) flag++; if (deb_check(release:"7.0", prefix:"libreoffice-l10n-st", reference:"1:3.5.4+dfsg2-0+deb7u11")) flag++; if (deb_check(release:"7.0", prefix:"libreoffice-l10n-sv", reference:"1:3.5.4+dfsg2-0+deb7u11")) flag++; if (deb_check(release:"7.0", prefix:"libreoffice-l10n-ta", reference:"1:3.5.4+dfsg2-0+deb7u11")) flag++; if (deb_check(release:"7.0", prefix:"libreoffice-l10n-te", reference:"1:3.5.4+dfsg2-0+deb7u11")) flag++; if (deb_check(release:"7.0", prefix:"libreoffice-l10n-tg", reference:"1:3.5.4+dfsg2-0+deb7u11")) flag++; if (deb_check(release:"7.0", prefix:"libreoffice-l10n-th", reference:"1:3.5.4+dfsg2-0+deb7u11")) flag++; if (deb_check(release:"7.0", prefix:"libreoffice-l10n-tn", reference:"1:3.5.4+dfsg2-0+deb7u11")) flag++; if (deb_check(release:"7.0", prefix:"libreoffice-l10n-tr", reference:"1:3.5.4+dfsg2-0+deb7u11")) flag++; if (deb_check(release:"7.0", prefix:"libreoffice-l10n-ts", reference:"1:3.5.4+dfsg2-0+deb7u11")) flag++; if (deb_check(release:"7.0", prefix:"libreoffice-l10n-ug", reference:"1:3.5.4+dfsg2-0+deb7u11")) flag++; if (deb_check(release:"7.0", prefix:"libreoffice-l10n-uk", reference:"1:3.5.4+dfsg2-0+deb7u11")) flag++; if (deb_check(release:"7.0", prefix:"libreoffice-l10n-uz", reference:"1:3.5.4+dfsg2-0+deb7u11")) flag++; if (deb_check(release:"7.0", prefix:"libreoffice-l10n-ve", reference:"1:3.5.4+dfsg2-0+deb7u11")) flag++; if (deb_check(release:"7.0", prefix:"libreoffice-l10n-vi", reference:"1:3.5.4+dfsg2-0+deb7u11")) flag++; if (deb_check(release:"7.0", prefix:"libreoffice-l10n-xh", reference:"1:3.5.4+dfsg2-0+deb7u11")) flag++; if (deb_check(release:"7.0", prefix:"libreoffice-l10n-za", reference:"1:3.5.4+dfsg2-0+deb7u11")) flag++; if (deb_check(release:"7.0", prefix:"libreoffice-l10n-zh-cn", reference:"1:3.5.4+dfsg2-0+deb7u11")) flag++; if (deb_check(release:"7.0", prefix:"libreoffice-l10n-zh-tw", reference:"1:3.5.4+dfsg2-0+deb7u11")) flag++; if (deb_check(release:"7.0", prefix:"libreoffice-l10n-zu", reference:"1:3.5.4+dfsg2-0+deb7u11")) flag++; if (deb_check(release:"7.0", prefix:"libreoffice-math", reference:"1:3.5.4+dfsg2-0+deb7u11")) flag++; if (deb_check(release:"7.0", prefix:"libreoffice-mysql-connector", reference:"1:3.5.4+dfsg2-0+deb7u11")) flag++; if (deb_check(release:"7.0", prefix:"libreoffice-officebean", reference:"1:3.5.4+dfsg2-0+deb7u11")) flag++; if (deb_check(release:"7.0", prefix:"libreoffice-ogltrans", reference:"1:3.5.4+dfsg2-0+deb7u11")) flag++; if (deb_check(release:"7.0", prefix:"libreoffice-pdfimport", reference:"1:3.5.4+dfsg2-0+deb7u11")) flag++; if (deb_check(release:"7.0", prefix:"libreoffice-presentation-minimizer", reference:"1:3.5.4+dfsg2-0+deb7u11")) flag++; if (deb_check(release:"7.0", prefix:"libreoffice-presenter-console", reference:"1:3.5.4+dfsg2-0+deb7u11")) flag++; if (deb_check(release:"7.0", prefix:"libreoffice-report-builder", reference:"1:3.5.4+dfsg2-0+deb7u11")) flag++; if (deb_check(release:"7.0", prefix:"libreoffice-report-builder-bin", reference:"1:3.5.4+dfsg2-0+deb7u11")) flag++; if (deb_check(release:"7.0", prefix:"libreoffice-script-provider-bsh", reference:"1:3.5.4+dfsg2-0+deb7u11")) flag++; if (deb_check(release:"7.0", prefix:"libreoffice-script-provider-js", reference:"1:3.5.4+dfsg2-0+deb7u11")) flag++; if (deb_check(release:"7.0", prefix:"libreoffice-script-provider-python", reference:"1:3.5.4+dfsg2-0+deb7u11")) flag++; if (deb_check(release:"7.0", prefix:"libreoffice-sdbc-postgresql", reference:"1:3.5.4+dfsg2-0+deb7u11")) flag++; if (deb_check(release:"7.0", prefix:"libreoffice-style-crystal", reference:"1:3.5.4+dfsg2-0+deb7u11")) flag++; if (deb_check(release:"7.0", prefix:"libreoffice-style-galaxy", reference:"1:3.5.4+dfsg2-0+deb7u11")) flag++; if (deb_check(release:"7.0", prefix:"libreoffice-style-hicontrast", reference:"1:3.5.4+dfsg2-0+deb7u11")) flag++; if (deb_check(release:"7.0", prefix:"libreoffice-style-oxygen", reference:"1:3.5.4+dfsg2-0+deb7u11")) flag++; if (deb_check(release:"7.0", prefix:"libreoffice-style-tango", reference:"1:3.5.4+dfsg2-0+deb7u11")) flag++; if (deb_check(release:"7.0", prefix:"libreoffice-wiki-publisher", reference:"1:3.5.4+dfsg2-0+deb7u11")) flag++; if (deb_check(release:"7.0", prefix:"libreoffice-writer", reference:"1:3.5.4+dfsg2-0+deb7u11")) flag++; if (deb_check(release:"7.0", prefix:"openoffice.org-dtd-officedocument1.0", reference:"1:3.5.4+dfsg2-0+deb7u11")) flag++; if (deb_check(release:"7.0", prefix:"python-uno", reference:"1:3.5.4+dfsg2-0+deb7u11")) flag++; if (deb_check(release:"7.0", prefix:"python3-uno", reference:"1:3.5.4+dfsg2-0+deb7u11")) flag++; if (deb_check(release:"7.0", prefix:"ttf-opensymbol", reference:"1:3.5.4+dfsg2-0+deb7u11")) flag++; if (flag) { if (report_verbosity > 0) security_warning(port:0, extra:deb_report_get()); else security_warning(0); exit(0); } else audit(AUDIT_HOST_NOT, "affected");
NASL family Windows NASL id LIBREOFFICE_601.NASL description The version of LibreOffice installed on the remote Windows host is either 5.x prior to 5.4.5 or 6.x prior to 6.0.1. It is, therefore, affected by the following vulnerabilities: - An arbitrary file read vulnerability exists in the COM.MICROSOFT.WEBSERVICE function due to improper validation of a URL input. An unauthenticated, remote attacker can exploit this, via a specially crafted file, to read arbitrary files and disclose sensitive information. (CVE-2018-6871) - A use after free vulnerability exists in the StgSmallStrm class due to the use of a short data type. An unauthenticated, remote attacker can exploit this, via a specially crafted file that uses the structured storage ole2 wrapper, to execute arbitrary code. (CVE-2018-10119) Note that Nessus has not tested for these issues but has instead relied only on the application last seen 2020-06-01 modified 2020-06-02 plugin id 122588 published 2019-03-04 reporter This script is Copyright (C) 2019 and is owned by Tenable, Inc. or an Affiliate thereof. source https://www.tenable.com/plugins/nessus/122588 title LibreOffice < 5.4.5 or 6.x < 6.0.1 Multiple Vulnerabilities NASL family SuSE Local Security Checks NASL id SUSE_SU-2018-1296-1.NASL description This update for libreoffice to 6.0.4.2 fixes lots of bugs and also the following issues: Security issues fixed : - CVE-2018-10120: The SwCTBWrapper::Read function in sw/source/filter/ww8/ww8toolbar.cxx did not validate a customizations index, which allowed remote attackers to cause a denial of service (heap-based buffer overflow with write access) or possibly have unspecified other impact via a crafted document that contains a certain Microsoft Word record. (bsc#1089706) - CVE-2018-10119: sot/source/sdstor/stgstrms.cxx used an incorrect integer data type in the StgSmallStrm class, which allowed remote attackers to cause a denial of service (use-after-free with write access) or possibly have unspecified other impact via a crafted document that uses the structured storage ole2 wrapper file format. (bsc#1089705) Other issues fixed : - DOCX import: missing table background color - Bring back offline help per popular demand as lto saves space we could use with it bsc#915996 Note that Tenable Network Security has extracted the preceding description block directly from the SUSE security advisory. Tenable has attempted to automatically clean and format it as much as possible without introducing additional issues. last seen 2020-06-01 modified 2020-06-02 plugin id 109862 published 2018-05-16 reporter This script is Copyright (C) 2018-2019 and is owned by Tenable, Inc. or an Affiliate thereof. source https://www.tenable.com/plugins/nessus/109862 title SUSE SLED12 Security Update : libreoffice (SUSE-SU-2018:1296-1) NASL family Debian Local Security Checks NASL id DEBIAN_DSA-4178.NASL description Two vulnerabilities were discovered in LibreOffice last seen 2020-06-01 modified 2020-06-02 plugin id 109220 published 2018-04-23 reporter This script is Copyright (C) 2018 and is owned by Tenable, Inc. or an Affiliate thereof. source https://www.tenable.com/plugins/nessus/109220 title Debian DSA-4178-1 : libreoffice - security update NASL family MacOS X Local Security Checks NASL id MACOS_LIBREOFFICE_601.NASL description The version of LibreOffice installed on the remote macOS host is either 5.x prior to 5.4.5 or 6.x prior to 6.0.1. It is, therefore, affected by the following vulnerabilities: - An arbitrary file read vulnerability exists in the COM.MICROSOFT.WEBSERVICE function due to improper validation of a URL input. An unauthenticated, remote attacker can exploit this, via a specially crafted file, to read arbitrary files and disclose sensitive information. (CVE-2018-6871) - A use after free vulnerability exists in the StgSmallStrm class due to the use of a short data type. An unauthenticated, remote attacker can exploit this, via a specially crafted file that uses the structured storage ole2 wrapper, to execute arbitrary code. (CVE-2018-10119) Note that Nessus has not tested for these issues but has instead relied only on the application last seen 2020-06-01 modified 2020-06-02 plugin id 122587 published 2019-03-04 reporter This script is Copyright (C) 2019 and is owned by Tenable, Inc. or an Affiliate thereof. source https://www.tenable.com/plugins/nessus/122587 title LibreOffice < 5.4.5 or 6.x < 6.0.1 Multiple Vulnerabilities (macOS)
Redhat
advisories |
| ||||
rpms |
|
References
- https://gerrit.libreoffice.org/#/c/48758/
- https://gerrit.libreoffice.org/#/c/48757/
- https://gerrit.libreoffice.org/#/c/48756/
- https://gerrit.libreoffice.org/#/c/48751/
- https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=5747
- https://www.libreoffice.org/about-us/security/advisories/cve-2018-10119/
- https://access.redhat.com/errata/RHSA-2018:3054
- https://usn.ubuntu.com/3883-1/
- https://www.debian.org/security/2018/dsa-4178
- https://lists.debian.org/debian-lts-announce/2018/04/msg00021.html
- https://gerrit.libreoffice.org/gitweb?p=core.git%3Ba=commit%3Bh=fdd41c995d1f719e92c6f083e780226114762f05