Bugzilla – Bug 1034568
VUL-0: CVE-2017-7870: libreoffice: LibreOffice before 2017-01-02 has an out-of-bounds write caused by a heap-basedbuffer overflow rela...
Last modified: 2018-05-03 22:38:37 UTC
CVE-2017-7870 LibreOffice before 2017-01-02 has an out-of-bounds write caused by a heap-based buffer overflow related to the tools::Polygon::Insert function in tools/source/generic/poly.cxx. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2017-7870 http://people.canonical.com/~ubuntu-security/cve/2017/CVE-2017-7870.html http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-7870 http://www.cvedetails.com/cve/CVE-2017-7870/ https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=372 http://www.securityfocus.com/bid/97671 https://github.com/LibreOffice/core/commit/62a97e6a561ce65e88d4c537a1b82c336f012722
Included in 5.3.0 and 5.2.5.
This is an autogenerated message for OBS integration: This bug (1034568) was mentioned in https://build.opensuse.org/request/show/489271 Factory / libreoffice
This is an autogenerated message for OBS integration: This bug (1034568) was mentioned in https://build.opensuse.org/request/show/490246 Factory / libreoffice
Update for SLE12 sent.
SUSE-SU-2017:1821-1: An update that solves 7 vulnerabilities and has 14 fixes is now available. Category: security (moderate) Bug References: 1015115,1015118,1015360,1017925,1021369,1021373,1028817,1034192,1034329,1034568,1035087,1036975,1042828,948058,959926,962777,963436,972777,975283,976831,989564 CVE References: CVE-2015-8947,CVE-2016-10327,CVE-2016-2052,CVE-2017-7870,CVE-2017-7882,CVE-2017-8358,CVE-2017-9433 Sources used: SUSE Linux Enterprise Workstation Extension 12-SP2 (src): libixion-0.12.1-12.1, libmwaw-0.3.11-9.1, liborcus-0.12.1-12.1, libreoffice-5.3.3.2-40.5.9, libstaroffice-0.0.3-2.1, libzmf-0.0.1-2.1, myspell-dictionaries-20170511-15.1 SUSE Linux Enterprise Software Development Kit 12-SP2 (src): libixion-0.12.1-12.1, libmwaw-0.3.11-9.1, liborcus-0.12.1-12.1, libreoffice-5.3.3.2-40.5.9 SUSE Linux Enterprise Desktop 12-SP2 (src): libixion-0.12.1-12.1, libmwaw-0.3.11-9.1, liborcus-0.12.1-12.1, libreoffice-5.3.3.2-40.5.9, libstaroffice-0.0.3-2.1, libzmf-0.0.1-2.1, myspell-dictionaries-20170511-15.1
openSUSE-SU-2017:1851-1: An update that solves 5 vulnerabilities and has 14 fixes is now available. Category: security (moderate) Bug References: 1015115,1015118,1015360,1017925,1021369,1021373,1028817,1034192,1034329,1034568,1035087,1036975,1042828,948058,959926,962777,972777,975283,976831 CVE References: CVE-2016-10327,CVE-2017-7870,CVE-2017-7882,CVE-2017-8358,CVE-2017-9433 Sources used: openSUSE Leap 42.2 (src): libixion-0.12.1-8.3.1, libmwaw-0.3.11-6.3.1, liborcus-0.12.1-9.3.1, libreoffice-5.3.3.2-18.6.2, libstaroffice-0.0.3-2.3.1, libzmf-0.0.1-2.1, myspell-dictionaries-20170511-6.3.1
SUSE-SU-2017:2315-1: An update that solves 7 vulnerabilities and has 19 fixes is now available. Category: security (moderate) Bug References: 1015115,1015118,1015360,1017925,1021369,1021373,1021675,1028817,1034192,1034329,1034568,1035087,1035589,1036975,1042828,1045339,947117,948058,954776,959926,962777,963436,972777,975283,976831,989564 CVE References: CVE-2015-8947,CVE-2016-10327,CVE-2016-2052,CVE-2017-7870,CVE-2017-7882,CVE-2017-8358,CVE-2017-9433 Sources used: SUSE Linux Enterprise Workstation Extension 12-SP3 (src): libixion-0.12.1-13.2.1, libmwaw-0.3.11-7.5.1, liborcus-0.12.1-10.5.1, libreoffice-5.3.5.2-43.5.4, libstaroffice-0.0.3-4.1, libzmf-0.0.1-4.1, myspell-dictionaries-20170511-16.2.1 SUSE Linux Enterprise Software Development Kit 12-SP3 (src): libixion-0.12.1-13.2.1, libmwaw-0.3.11-7.5.1, liborcus-0.12.1-10.5.1, libreoffice-5.3.5.2-43.5.4 SUSE Linux Enterprise Desktop 12-SP3 (src): libixion-0.12.1-13.2.1, libmwaw-0.3.11-7.5.1, liborcus-0.12.1-10.5.1, libreoffice-5.3.5.2-43.5.4, libstaroffice-0.0.3-4.1, libzmf-0.0.1-4.1, myspell-dictionaries-20170511-16.2.1
openSUSE-SU-2017:2488-1: An update that solves 7 vulnerabilities and has 19 fixes is now available. Category: security (moderate) Bug References: 1015115,1015118,1015360,1017925,1021369,1021373,1021675,1028817,1034192,1034329,1034568,1035087,1035589,1036975,1042828,1045339,947117,948058,954776,959926,962777,963436,972777,975283,976831,989564 CVE References: CVE-2015-8947,CVE-2016-10327,CVE-2016-2052,CVE-2017-7870,CVE-2017-7882,CVE-2017-8358,CVE-2017-9433 Sources used: openSUSE Leap 42.3 (src): libreoffice-5.3.5.2-3.4 openSUSE Leap 42.2 (src): libreoffice-5.3.5.2-18.9.4
released