CVE-2017-9806

CWE-787Out-of-bounds Write10 documents8 sources
Severity
7.8HIGH
EPSS
1.3%
top 19.90%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 20
Latest updateMay 13

Description

A vulnerability in the OpenOffice Writer DOC file parser before 4.1.4, and specifically in the WW8Fonts Constructor, allows attackers to craft malicious documents that cause denial of service (memory corruption and application crash) potentially resulting in arbitrary code execution.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages3 packages

NVDapache/openoffice< 4.1.4
CVEListV5apache_software_foundation/apache_openoffice4.0.0 to 4.1.3, and some previous releases, including some using our old OpenOffice.org brand
Debianlibreoffice< 1:3.4.3-1+3

🔴Vulnerability Details

3
GHSA
GHSA-f454-5wwx-q3hc: A vulnerability in the OpenOffice Writer DOC file parser before 42022-05-13
OSV
CVE-2017-9806: A vulnerability in the OpenOffice Writer DOC file parser before 42017-11-20
CVEList
CVE-2017-9806: A vulnerability in the OpenOffice Writer DOC file parser before 42017-11-20

📋Vendor Advisories

2
Red Hat
libreoffice: Out-of-bounds write in the WW8Fonts::WW8Fonts functionality2017-10-26
Debian
CVE-2017-9806: libreoffice - A vulnerability in the OpenOffice Writer DOC file parser before 4.1.4, and speci...2017

💬Community

2
Bugzilla
CVE-2017-12607 CVE-2017-12608 CVE-2017-9806 libreoffice: various flaws [fedora-all]2017-10-31
Bugzilla
CVE-2017-9806 libreoffice: Out-of-bounds write in the WW8Fonts::WW8Fonts functionality2017-10-31
CVE-2017-9806 (HIGH CVSS 7.8) | A vulnerability in the OpenOffice W | cvebase.io