First published: Mon Nov 20 2017(Updated: )
A vulnerability in OpenOffice's PPT file parser before 4.1.4, and specifically in PPTStyleSheet, allows attackers to craft malicious documents that cause denial of service (memory corruption and application crash) potentially resulting in arbitrary code execution.
Credit: security@apache.org
Affected Software | Affected Version | How to fix |
---|---|---|
debian/libreoffice | 1:6.1.5-3+deb10u7 1:6.1.5-3+deb10u10 1:7.0.4-4+deb11u7 4:7.4.7-1 4:7.5.6-1 4:7.5.8~rc1-1 | |
Apache OpenOffice | <4.1.4 | |
Debian Debian Linux | =7.0 | |
Debian Debian Linux | =8.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-12607 is a vulnerability in OpenOffice's PPT file parser before version 4.1.4 that can allow attackers to craft malicious documents to cause denial of service and potentially execute arbitrary code.
CVE-2017-12607 has a severity value of 7.8, which is considered high.
The affected software includes Apache OpenOffice up to version 4.1.4 and LibreOffice versions 1:6.1.5-3+deb10u7, 1:6.1.5-3+deb10u10, 1:7.0.4-4+deb11u7, 4:7.4.7-1, 4:7.5.6-1, and 4:7.5.8~rc1-1.
To fix CVE-2017-12607, it is recommended to update to the latest version of the affected software, such as OpenOffice 4.1.4 or later, or LibreOffice 6.1.5-3+deb10u7 or later.
You can find more information about CVE-2017-12607 in the following references: [Talos Intelligence Report](https://www.talosintelligence.com/reports/TALOS-2017-0300), [LibreOffice Security Advisories](https://www.libreoffice.org/about-us/security/advisories/CVE-2017-12607), [LibreOffice Source Code Commit](https://cgit.freedesktop.org/libreoffice/core/commit/?id=334dba623dfb0c4fb2b5292c2d03741b7b33aef1).