CVE-2017-12607

CWE-787Out-of-bounds Write10 documents8 sources
Severity
7.8HIGH
EPSS
0.8%
top 25.28%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 20
Latest updateMay 13

Description

A vulnerability in OpenOffice's PPT file parser before 4.1.4, and specifically in PPTStyleSheet, allows attackers to craft malicious documents that cause denial of service (memory corruption and application crash) potentially resulting in arbitrary code execution.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages4 packages

NVDapache/openoffice< 4.1.4
CVEListV5apache_software_foundation/apache_openoffice4.0.0 to 4.1.3, and some previous releases, including some using our old OpenOffice.org brand
Debianlibreoffice< 1:5.0.2-1+3
Ubuntulibreoffice< 1:4.2.8-0ubuntu5.2

Also affects: Debian Linux 7.0, 8.0

🔴Vulnerability Details

4
GHSA
GHSA-c68g-xg99-c8q7: A vulnerability in OpenOffice's PPT file parser before 42022-05-13
CVEList
CVE-2017-12607: A vulnerability in OpenOffice's PPT file parser before 42017-11-20
OSV
CVE-2017-12607: A vulnerability in OpenOffice's PPT file parser before 42017-11-20
OSV
libreoffice vulnerabilities2017-11-02

📋Vendor Advisories

3
Ubuntu
LibreOffice vulnerabilities2017-11-02
Red Hat
libreoffice: Out-of-bounds write in the PPTStyleSheet::PPTStyleSheet functionality2017-10-26
Debian
CVE-2017-12607: libreoffice - A vulnerability in OpenOffice's PPT file parser before 4.1.4, and specifically i...2017

💬Community

2
Bugzilla
CVE-2017-12607 libreoffice: Out-of-bounds write in the PPTStyleSheet::PPTStyleSheet functionality2017-10-31
Bugzilla
CVE-2017-12607 CVE-2017-12608 CVE-2017-9806 libreoffice: various flaws [fedora-all]2017-10-31
CVE-2017-12607 (HIGH CVSS 7.8) | A vulnerability in OpenOffice's PPT | cvebase.io