CVE-2017-7870
libreoffice: Heap-buffer-overflow in tools::Polygon::Insert
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
LibreOffice before 2017-01-02 has an out-of-bounds write caused by a heap-based buffer overflow related to the tools::Polygon::Insert function in tools/source/generic/poly.cxx.
LibreOffice en versiones anteriores a 02-01-2017 tiene una escritura fuera de límites provocado por un desbordamiento de búfer basado en memoria dinámica en relación con la función tools::Polygon::Insert en tools/source/generic/poly.cxx
An out-of-bounds write flaw was found in the way Libreoffice rendered certain documents containing Polygon images. By tricking a user into opening a specially crafted LibreOffice file, an attacker could possibly use this flaw to execute arbitrary code with the privileges of the user opening the file.
LibreOffice is an open source, community-developed office productivity suite. It includes key desktop applications, such as a word processor, a spreadsheet, a presentation manager, a formula editor, and a drawing program. LibreOffice replaces OpenOffice and provides a similar but enhanced and extended office suite. Security Fix: An out-of-bounds write flaw was found in the way Libreoffice rendered certain documents containing Polygon images. By tricking a user into opening a specially crafted LibreOffice file, an attacker could possibly use this flaw to execute arbitrary code with the privileges of the user opening the file.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2017-04-14 CVE Reserved
- 2017-04-14 CVE Published
- 2024-08-05 CVE Updated
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-122: Heap-based Buffer Overflow
- CWE-787: Out-of-bounds Write
CAPEC
References (10)
URL | Tag | Source |
---|---|---|
http://www.libreoffice.org/about-us/security/advisories/cve-2017-7870 | X_refsource_confirm | |
http://www.securityfocus.com/bid/97671 | Third Party Advisory | |
http://www.securitytracker.com/id/1039029 | Vdb Entry | |
https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=372 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://github.com/LibreOffice/core/commit/62a97e6a561ce65e88d4c537a1b82c336f012722 | 2018-01-05 |
URL | Date | SRC |
---|---|---|
http://www.debian.org/security/2017/dsa-3837 | 2018-01-05 | |
https://access.redhat.com/errata/RHSA-2017:1975 | 2018-01-05 | |
https://security.gentoo.org/glsa/201706-28 | 2018-01-05 | |
https://access.redhat.com/security/cve/CVE-2017-7870 | 2017-08-01 | |
https://bugzilla.redhat.com/show_bug.cgi?id=1444061 | 2017-08-01 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Libreoffice Search vendor "Libreoffice" | Libreoffice Search vendor "Libreoffice" for product "Libreoffice" | <= 5.3.0.0 Search vendor "Libreoffice" for product "Libreoffice" and version " <= 5.3.0.0" | beta2 |
Affected
|