CVE-2017-9806

Title: CVE-2017-9806: Out-of-Bounds Write in Writer's WW8Fonts Constructor

Announced: October 27, 2017

Fixed in: LibreOffice 3.4.3

Description:

Prior to version 3.4.3 a vulnerability exists in the DOC font descriptor parser, allowing attackers to craft malicious documents that cause denial of service (memory corruption and application crash) potentially resulting in arbitrary code execution. Users should already have upgraded to versions >= 3.4.3 due to earlier advisories.

References:

Latest Tweets

@libreoffice
@tdforg