Bugzilla will be upgraded to version 5.0. The upgrade date is tentatively scheduled for 2 December 2018, pending final testing and feedback.
Bug 1507803 - (CVE-2017-9806) CVE-2017-9806 libreoffice: Out-of-bounds write in the WW8Fonts::WW8Fonts functionality
CVE-2017-9806 libreoffice: Out-of-bounds write in the WW8Fonts::WW8Fonts func...
Status: CLOSED NOTABUG
Product: Security Response
Classification: Other
Component: vulnerability (Show other bugs)
unspecified
All Linux
high Severity high
: ---
: ---
Assigned To: Red Hat Product Security
impact=important,public=20171026,repo...
: Security
Depends On: 1507808
Blocks: 1507560
  Show dependency treegraph
 
Reported: 2017-10-31 04:19 EDT by Andrej Nemec
Modified: 2017-10-31 06:00 EDT (History)
6 users (show)

See Also:
Fixed In Version: libreoffice 3.4.3
Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of:
Environment:
Last Closed: 2017-10-31 05:19:54 EDT
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)

  None (edit)
Description Andrej Nemec 2017-10-31 04:19:12 EDT
An exploitable out of bound write vulnerability exists in the WW8Fonts::WW8Fonts functionality of Apache OpenOffice 4.1.3. A specially crafted doc file can cause an out of bound write potentially resulting in arbitrary code execution. An attacker can send/provide a malicious doc file to trigger this vulnerability.

External References:

https://www.talosintelligence.com/reports/TALOS-2017-0295
https://www.openoffice.org/security/cves/CVE-2017-9806.html
https://www.libreoffice.org/about-us/security/advisories/CVE-2017-9806
Comment 1 Andrej Nemec 2017-10-31 04:23:23 EDT
Created libreoffice tracking bugs for this issue:

Affects: fedora-all [bug 1507808]
Comment 2 David Tardon 2017-10-31 04:45:04 EDT
Is there any reproducer? Or even a hint whether libreoffice is vulnerable too? It seems to me that this was addressed by https://gerrit.libreoffice.org/gitweb?p=core.git;a=commitdiff_plain;h=bb494d6bd8c5868f34bd8f9444ed3eb401145f10 ~6 years ago...
Comment 3 David Tardon 2017-10-31 05:06:48 EDT
Caolan confirms this is fixed by the mentioned commit, so no current Fedora is vulnerable.
Comment 4 Huzaifa S. Sidhpurwala 2017-10-31 05:19:54 EDT
As per Libreoffice advisory mentioned in comment 0 , this issue was fixed in LO version 3.4.3, hence not version of Libreoffice shipped with Red Hat Enterprise Linux or Fedora is affected.

Note You need to log in before you can comment on or make changes to this bug.