CVE-2017-12607 is a high-severity vulnerability affecting Apache OpenOffice versions prior to 4.1.4, specifically within its PPT file parser. An attacker can exploit this by crafting a malicious document, leading to memory corruption, application crashes (denial of service), and potentially arbitrary code execution. The attack requires user interaction (opening the malicious file) but has a high impact on confidentiality, integrity, and availability. While no public exploit code or active exploitation has been observed, the vulnerability has garnered some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 4.1.4CPE matchmatch criteria | cpe:2.3:a:apache:openoffice:*:*:*:*:*:*:*:* | ||
7.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:* | ||
8.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
libreoffice: Out-of-bounds write in the PPTStyleSheet::PPTStyleSheet functionality
Oct 26, 2017LotusWordPro Bounds overflows in LwpTocSuperLayout processing
Out-of-Bounds Write in Impress' PPT Filter
LotusWordPro Bounds overflows in LwpTocSuperLayout processing
Out-of-Bounds Write in Impress' PPT Filter
Out-of-Bounds Write in Impress' PPT Filter
Out-of-Bounds Write in Impress' PPT Filter
Out-of-Bounds Write in Impress' PPT Filter
Out-of-Bounds Write in Impress' PPT Filter