CVE-2017-7870: Buffer Overflow
LibreOffice before 2017-01-02 has an out-of-bounds write caused by a heap-based buffer overflow related to the tools::Polygon::Insert function in tools/source/generic/poly.cxx.
Other sources
LibreOffice has an out-of-bounds write caused by a heap-based buffer overflow related to the tools::Polygon::Insert function in tools/source/generic/poly.cxx.
References:
https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=372
Upstream patch:
https://github.com/LibreOffice/core/commit/62a97e6a561ce65e88d4c537a1b82c336f012722
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/libreofficeto a version that resolves this vulnerability.Fixed in 5.2.5 - Upgrade
Upgrade
redhat/libreofficeto a version that resolves this vulnerability.Fixed in 5.3.0 - Upgrade
Upgrade
LibreOfficeto a version that resolves this vulnerability.Fixed in 2017-01-02 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch 62a97e6a561ce65e88d4c537a1b82c336f012722
Event History
Frequently Asked Questions
What is the severity of CVE-2017-7870?
CVE-2017-7870 has a medium severity rating due to its potential to cause a heap-based buffer overflow.
How do I fix CVE-2017-7870?
To fix CVE-2017-7870, upgrade LibreOffice to versions 5.2.5 or 5.3.0 and later.
Which versions of LibreOffice are affected by CVE-2017-7870?
Versions of LibreOffice prior to 5.2.5 and 5.3.0 are affected by CVE-2017-7870.
What vulnerability is associated with the tools::Polygon::Insert function?
CVE-2017-7870 is associated with an out-of-bounds write caused by heap-based buffer overflow in the tools::Polygon::Insert function.
Is CVE-2017-7870 a known issue in Red Hat software?
Yes, CVE-2017-7870 is a known vulnerability affecting specific versions of LibreOffice distributed by Red Hat.