First published: Sun Apr 30 2017(Updated: )
LibreOffice before 2017-03-17 has an out-of-bounds write caused by a heap-based buffer overflow related to the ReadJPEG function in vcl/source/filter/jpeg/jpegc.cxx.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
The Document Foundation LibreOffice | <=5.2.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-8358 is considered to have a high severity due to the potential for remote code execution.
To fix CVE-2017-8358, update LibreOffice to version 5.2.7 or later.
CVE-2017-8358 is caused by an out-of-bounds write due to a heap-based buffer overflow in the ReadJPEG function.
CVE-2017-8358 affects LibreOffice versions up to and including 5.2.6.
CVE-2017-8358 is a remote vulnerability, as it can be exploited through malicious JPEG files.