Advisories ยป MGASA-2017-0358

Updated libwpd packages fix security vulnerability

Publication date: 05 Oct 2017
Modification date: 05 Oct 2017
Type: security
Affected Mageia releases : 5 , 6
CVE: CVE-2017-14226

Description

WP1StylesListener.cpp, WP5StylesListener.cpp, and WP42StylesListener.cpp
in libwpd 0.10.1 mishandle iterators, which allows remote attackers to
cause a denial of service (heap-based buffer over-read in the
WPXTableList class in WPXTable.cpp). This vulnerability can be triggered
in LibreOffice before 5.3.7. It may lead to suffering a remote attack
against a LibreOffice application. (CVE-2017-14226)
                

References

SRPMS

6/core

5/core