CVE-2017-12608: High severity Apache OpenOffice vulnerability
A vulnerability in Apache OpenOffice Writer DOC file parser before 4.1.4, and specifically in ImportOldFormatStyles, allows attackers to craft malicious documents that cause denial of service (memory corruption and application crash) potentially resulting in arbitrary code execution.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2017-12608?
CVE-2017-12608 is a vulnerability in Apache OpenOffice Writer DOC file parser before version 4.1.4, which allows attackers to craft malicious documents that can cause denial of service, memory corruption, and application crashes, potentially leading to arbitrary code execution.
How does CVE-2017-12608 affect Apache OpenOffice?
CVE-2017-12608 affects Apache OpenOffice versions before 4.1.4, specifically in the ImportOldFormatStyles function of the DOC file parser.
What is the severity of CVE-2017-12608?
CVE-2017-12608 has a severity rating of 7.8 out of 10, which is considered high.
How can CVE-2017-12608 be fixed?
To fix CVE-2017-12608, users should update their Apache OpenOffice installations to version 4.1.4 or newer.
Where can I find more information about CVE-2017-12608?
More information about CVE-2017-12608 can be found at the following references: [Talos Intelligence](https://www.talosintelligence.com/reports/TALOS-2017-0301), [LibreOffice Security Advisories](https://www.libreoffice.org/about-us/security/advisories/CVE-2017-12608), [LibreOffice Commit Details](https://gerrit.libreoffice.org/gitweb?p=core.git;a=commitdiff_plain;h=42a709d1ef647aab9a1c9422b4e25ecaee857aba).