CVE-2017-9806 is a memory corruption vulnerability in the Apache OpenOffice Writer DOC file parser (specifically the WW8Fonts Constructor) prior to version 4.1.4. This allows attackers to craft malicious documents that can lead to denial of service (application crash) and potentially arbitrary code execution. With a CVSS score of 7.8 (High), it requires user interaction (opening a malicious document) but has a low attack complexity, posing a significant risk to confidentiality, integrity, and availability. While no public exploit code or active exploitation has been identified, it has received some community and media attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 4.1.4CPE matchmatch criteria | cpe:2.3:a:apache:openoffice:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
libreoffice: Out-of-bounds write in the WW8Fonts::WW8Fonts functionality
Oct 26, 2017Out-of-Bounds Write in Writer's WW8Fonts Constructor
Out-of-Bounds Write in Writer's WW8Fonts Constructor
Out-of-Bounds Write in Writer's WW8Fonts Constructor
Out-of-Bounds Write in Writer's WW8Fonts Constructor
Out-of-Bounds Write in Writer's WW8Fonts Constructor
Out-of-Bounds Write in Writer's WW8Fonts Constructor