Bug 1034568 - (CVE-2017-7870) VUL-0: CVE-2017-7870: libreoffice: LibreOffice before 2017-01-02 has an out-of-bounds write caused by a heap-basedbuffer overflow rela...
(CVE-2017-7870)
VUL-0: CVE-2017-7870: libreoffice: LibreOffice before 2017-01-02 has an out-o...
Status: RESOLVED FIXED
Classification: Novell Products
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents
unspecified
Other Other
: P3 - Medium : Normal
: ---
Assigned To: Security Team bot
Security Team bot
https://smash.suse.de/issue/183679/
CVSSv2:SUSE:CVE-2017-7870:6.8:(AV:N/A...
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2017-04-18 07:36 UTC by Marcus Meissner
Modified: 2018-05-03 22:38 UTC (History)
1 user (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Comment 1 Tomáš Chvátal 2017-04-19 09:30:02 UTC
Included in 5.3.0 and 5.2.5.
Comment 2 Bernhard Wiedemann 2017-04-19 10:01:00 UTC
This is an autogenerated message for OBS integration:
This bug (1034568) was mentioned in
https://build.opensuse.org/request/show/489271 Factory / libreoffice
Comment 3 Bernhard Wiedemann 2017-04-24 12:01:26 UTC
This is an autogenerated message for OBS integration:
This bug (1034568) was mentioned in
https://build.opensuse.org/request/show/490246 Factory / libreoffice
Comment 4 Tomáš Chvátal 2017-05-16 10:49:13 UTC
Update for SLE12 sent.
Comment 5 Swamp Workflow Management 2017-07-08 01:12:46 UTC
SUSE-SU-2017:1821-1: An update that solves 7 vulnerabilities and has 14 fixes is now available.

Category: security (moderate)
Bug References: 1015115,1015118,1015360,1017925,1021369,1021373,1028817,1034192,1034329,1034568,1035087,1036975,1042828,948058,959926,962777,963436,972777,975283,976831,989564
CVE References: CVE-2015-8947,CVE-2016-10327,CVE-2016-2052,CVE-2017-7870,CVE-2017-7882,CVE-2017-8358,CVE-2017-9433
Sources used:
SUSE Linux Enterprise Workstation Extension 12-SP2 (src):    libixion-0.12.1-12.1, libmwaw-0.3.11-9.1, liborcus-0.12.1-12.1, libreoffice-5.3.3.2-40.5.9, libstaroffice-0.0.3-2.1, libzmf-0.0.1-2.1, myspell-dictionaries-20170511-15.1
SUSE Linux Enterprise Software Development Kit 12-SP2 (src):    libixion-0.12.1-12.1, libmwaw-0.3.11-9.1, liborcus-0.12.1-12.1, libreoffice-5.3.3.2-40.5.9
SUSE Linux Enterprise Desktop 12-SP2 (src):    libixion-0.12.1-12.1, libmwaw-0.3.11-9.1, liborcus-0.12.1-12.1, libreoffice-5.3.3.2-40.5.9, libstaroffice-0.0.3-2.1, libzmf-0.0.1-2.1, myspell-dictionaries-20170511-15.1
Comment 6 Swamp Workflow Management 2017-07-12 22:11:34 UTC
openSUSE-SU-2017:1851-1: An update that solves 5 vulnerabilities and has 14 fixes is now available.

Category: security (moderate)
Bug References: 1015115,1015118,1015360,1017925,1021369,1021373,1028817,1034192,1034329,1034568,1035087,1036975,1042828,948058,959926,962777,972777,975283,976831
CVE References: CVE-2016-10327,CVE-2017-7870,CVE-2017-7882,CVE-2017-8358,CVE-2017-9433
Sources used:
openSUSE Leap 42.2 (src):    libixion-0.12.1-8.3.1, libmwaw-0.3.11-6.3.1, liborcus-0.12.1-9.3.1, libreoffice-5.3.3.2-18.6.2, libstaroffice-0.0.3-2.3.1, libzmf-0.0.1-2.1, myspell-dictionaries-20170511-6.3.1
Comment 7 Swamp Workflow Management 2017-08-31 22:11:32 UTC
SUSE-SU-2017:2315-1: An update that solves 7 vulnerabilities and has 19 fixes is now available.

Category: security (moderate)
Bug References: 1015115,1015118,1015360,1017925,1021369,1021373,1021675,1028817,1034192,1034329,1034568,1035087,1035589,1036975,1042828,1045339,947117,948058,954776,959926,962777,963436,972777,975283,976831,989564
CVE References: CVE-2015-8947,CVE-2016-10327,CVE-2016-2052,CVE-2017-7870,CVE-2017-7882,CVE-2017-8358,CVE-2017-9433
Sources used:
SUSE Linux Enterprise Workstation Extension 12-SP3 (src):    libixion-0.12.1-13.2.1, libmwaw-0.3.11-7.5.1, liborcus-0.12.1-10.5.1, libreoffice-5.3.5.2-43.5.4, libstaroffice-0.0.3-4.1, libzmf-0.0.1-4.1, myspell-dictionaries-20170511-16.2.1
SUSE Linux Enterprise Software Development Kit 12-SP3 (src):    libixion-0.12.1-13.2.1, libmwaw-0.3.11-7.5.1, liborcus-0.12.1-10.5.1, libreoffice-5.3.5.2-43.5.4
SUSE Linux Enterprise Desktop 12-SP3 (src):    libixion-0.12.1-13.2.1, libmwaw-0.3.11-7.5.1, liborcus-0.12.1-10.5.1, libreoffice-5.3.5.2-43.5.4, libstaroffice-0.0.3-4.1, libzmf-0.0.1-4.1, myspell-dictionaries-20170511-16.2.1
Comment 8 Swamp Workflow Management 2017-09-15 10:18:26 UTC
openSUSE-SU-2017:2488-1: An update that solves 7 vulnerabilities and has 19 fixes is now available.

Category: security (moderate)
Bug References: 1015115,1015118,1015360,1017925,1021369,1021373,1021675,1028817,1034192,1034329,1034568,1035087,1035589,1036975,1042828,1045339,947117,948058,954776,959926,962777,963436,972777,975283,976831,989564
CVE References: CVE-2015-8947,CVE-2016-10327,CVE-2016-2052,CVE-2017-7870,CVE-2017-7882,CVE-2017-8358,CVE-2017-9433
Sources used:
openSUSE Leap 42.3 (src):    libreoffice-5.3.5.2-3.4
openSUSE Leap 42.2 (src):    libreoffice-5.3.5.2-18.9.4
Comment 9 Marcus Meissner 2017-10-26 06:12:40 UTC
released