{"id":"CVE-2018-14939","details":"The get_app_path function in desktop/unx/source/start.c in LibreOffice through 6.0.5 mishandles the realpath function in certain environments such as FreeBSD libc, which might allow attackers to cause a denial of service (buffer overflow and application crash) or possibly have unspecified other impact if LibreOffice is automatically launched during web browsing with pathnames controlled by a remote web site.","modified":"2026-07-08T14:14:57.969063Z","published":"2018-08-05T18:29:00.207Z","references":[{"type":"ADVISORY","url":"http://www.securityfocus.com/bid/105047"},{"type":"ADVISORY","url":"https://bugs.documentfoundation.org/show_bug.cgi?id=118514"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/libreoffice/core","events":[{"introduced":"0"},{"last_affected":"12d1b08aac8cc8c3176040efc7290377e380f0c4"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"last_affected":"6.0.5"}],"source":"CPE_RANGE","cpe":"cpe:2.3:a:libreoffice:libreoffice:*:*:*:*:*:*:*:*"}}],"versions":["cp-6.0-5","cp-6.0-3","cp-6.0-2","cp-6.0-1","cp-6.0-branch-point","libreoffice-6-0-branch-point","gpg4libre-review-5.4.99","libreoffice-5-4-branch-point","libreoffice-5-3-branch-point","libreoffice-5-2-branch-point","libreoffice-5-1-branch-point","libreoffice-5-0-branch-point","libreoffice-4-4-branch-point","libreoffice-4-3-branch-point","sdremote-2.0.0","libreoffice-4-2-branch-point","libreoffice-4-2-milestone-1","libreoffice-4-1-branch-point","libreoffice-4-0-branch-point","libreoffice-3-6-branch-point","libreoffice-3.5.0.0","libreoffice-3-5-branch-point","windows_build_successful_2011_11_08","MELD_LIBREOFFICE_REPOS"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-14939.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}