CVE-2017-12608

CWE-787Out-of-bounds Write10 documents8 sources
Severity
7.8HIGH
EPSS
1.1%
top 21.57%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 20
Latest updateMay 13

Description

A vulnerability in Apache OpenOffice Writer DOC file parser before 4.1.4, and specifically in ImportOldFormatStyles, allows attackers to craft malicious documents that cause denial of service (memory corruption and application crash) potentially resulting in arbitrary code execution.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages3 packages

NVDapache/openoffice< 4.1.4
CVEListV5apache_software_foundation/apache_openoffice4.0.0 to 4.1.3, and some previous releases, including some using our old OpenOffice.org brand
Debianlibreoffice< 1:5.0.2-1+3

Also affects: Debian Linux 7.0, 8.0

🔴Vulnerability Details

4
GHSA
GHSA-hwpq-wfjf-957h: A vulnerability in Apache OpenOffice Writer DOC file parser before 42022-05-13
OSV
CVE-2017-12608: A vulnerability in Apache OpenOffice Writer DOC file parser before 42017-11-20
CVEList
CVE-2017-12608: A vulnerability in Apache OpenOffice Writer DOC file parser before 42017-11-20
OSV
libreoffice vulnerabilities2017-11-02

📋Vendor Advisories

3
Ubuntu
LibreOffice vulnerabilities2017-11-02
Red Hat
libreoffice: Out-of-bounds write in the WW8RStyle::ImportOldFormatStyles functionality2017-10-26
Debian
CVE-2017-12608: libreoffice - A vulnerability in Apache OpenOffice Writer DOC file parser before 4.1.4, and sp...2017

💬Community

2
Bugzilla
CVE-2017-12608 libreoffice: Out-of-bounds write in the WW8RStyle::ImportOldFormatStyles functionality2017-10-31
Bugzilla
CVE-2017-12607 CVE-2017-12608 CVE-2017-9806 libreoffice: various flaws [fedora-all]2017-10-31
CVE-2017-12608 (HIGH CVSS 7.8) | A vulnerability in Apache OpenOffic | cvebase.io