{"id":"ECHO-a8e4-9962-ca51","summary":"Windows-only. The information disclosure is Windows automatically opening\nan SMB connection and sending the user's NTLM credentials when a document\nreferences file://\u003chost\u003e/\u003cshare\u003e (e.g. xlink:href in an .odt). On Linux,\nLibreOffice does not reach SMB for such URLs and there is no automatic\nNTLM authentication, so nothing is disclosed. Upstream additionally\nrestricted such accesses to trusted locations. Debian marks this issue\nunimportant (\"generic behaviour of accessing remote SMB shares\").\n\nhttps://security-tracker.debian.org/tracker/CVE-2018-10583\n","modified":"2026-09-29T11:45:37.691987242Z","published":"2026-04-20T21:16:23.156061Z","withdrawn":"2026-09-29T11:00:03.921Z","upstream":["CVE-2018-10583"],"references":[{"type":"WEB","url":"https://advisory.echohq.com/cve/CVE-2018-10583"}],"affected":[{"package":{"name":"libreoffice","ecosystem":"Echo","purl":"pkg:deb/echo/libreoffice"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4:25.2.3-2+deb13u6"}]}],"database_specific":{"source":"https://advisory.echohq.com/osv/ECHO-a8e4-9962-ca51.json"}}],"schema_version":"1.9.0"}