First published: Mon Nov 20 2017(Updated: )
A vulnerability in the OpenOffice Writer DOC file parser before 4.1.4, and specifically in the WW8Fonts Constructor, allows attackers to craft malicious documents that cause denial of service (memory corruption and application crash) potentially resulting in arbitrary code execution.
Credit: security@apache.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apache OpenOffice | <4.1.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-9806 is a vulnerability in the OpenOffice Writer DOC file parser that allows attackers to craft malicious documents, potentially resulting in arbitrary code execution.
CVE-2017-9806 has a severity rating of 7.8 (High).
To fix CVE-2017-9806, it is recommended to update to Apache OpenOffice version 4.1.4 or later.
The affected software is Apache OpenOffice versions prior to 4.1.4.
Yes, you can find more information about CVE-2017-9806 at the following references: [http://www.openoffice.org/security/cves/CVE-2017-9806.html](http://www.openoffice.org/security/cves/CVE-2017-9806.html) and [http://www.securityfocus.com/bid/101585](http://www.securityfocus.com/bid/101585).