CVE-2017-14226: High severity LibreOffice Libreoffice vulnerability
WP1StylesListener.cpp, WP5StylesListener.cpp, and WP42StylesListener.cpp in libwpd 0.10.1 mishandle iterators, which allows remote attackers to cause a denial of service (heap-based buffer over-read in the WPXTableList class in WPXTable.cpp). This vulnerability can be triggered in LibreOffice before 5.3.7. It may lead to suffering a remote attack against a LibreOffice application.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2017-14226?
CVE-2017-14226 has been classified with a severity rating that indicates a denial of service risk due to improper iterator handling.
How do I fix CVE-2017-14226?
To fix CVE-2017-14226, update LibreOffice to a version later than 5.3.6 or ensure that you are using a patched version of libwpd beyond 0.10.1.
What systems are affected by CVE-2017-14226?
CVE-2017-14226 affects LibreOffice versions up to and including 5.3.6 and specifically libwpd version 0.10.1.
Is CVE-2017-14226 exploitable by remote attackers?
Yes, CVE-2017-14226 can be exploited by remote attackers to cause a denial of service.
What kind of attack does CVE-2017-14226 facilitate?
CVE-2017-14226 facilitates heap-based buffer over-read attacks that can lead to application crashes.