CVE-2017-7856: Buffer Overflow
Published Apr 14, 2017
·Updated
LibreOffice before 2017-03-11 has an out-of-bounds write caused by a heap-based buffer overflow in the SVMConverter::ImplConvertFromSVM1 function in vcl/source/gdi/svmconverter.cxx.
Affected Software
1 affected component
LibreOffice Libreoffice<=5.2.6.1
Remediation
Event History
Apr 14, 2017
CVE Published
via MITRE·04:30 AM
Data Sourced
via MITRE·04:30 AM
Description
Data Sourced
via NVD·04:59 AM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2017-7856?
CVE-2017-7856 has a high severity rating due to the potential for remote code execution.
2
How do I fix CVE-2017-7856?
To fix CVE-2017-7856, update LibreOffice to a version newer than 5.2.6.1.
3
What causes CVE-2017-7856?
CVE-2017-7856 is caused by a heap-based buffer overflow in the SVMConverter::ImplConvertFromSVM1 function.
4
Which versions of LibreOffice are affected by CVE-2017-7856?
LibreOffice versions up to and including 5.2.6.1 are affected by CVE-2017-7856.
5
Is CVE-2017-7856 exploitable?
Yes, CVE-2017-7856 is considered exploitable in certain conditions, allowing attackers to execute arbitrary code.