Bugzilla – Bug 1065982
VUL-1: CVE-2017-12608: libreoffice: Out-of-bounds write in the WW8RStyle::ImportOldFormatStyles functionality
Last modified: 2018-02-12 21:10:13 UTC
rh#1507806 An exploitable out-of-bounds write vulnerability exists in the WW8RStyle::ImportOldFormatStyles functionality of Apache OpenOffice 4.1.3. A specially crafted doc file can cause a out-of-bounds write resulting in arbitrary code execution. An attacker can send/provide malicious doc file to trigger this vulnerability. References: https://www.talosintelligence.com/reports/TALOS-2017-0301 https://www.openoffice.org/security/cves/CVE-2017-12608.html https://www.libreoffice.org/about-us/security/advisories/CVE-2017-12608 https://bugzilla.redhat.com/show_bug.cgi?id=1507806 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2017-12608 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-12608
Not on our products, affects 5.0.1 and older.
upstream fixed