Critical severity9.8NVD Advisory· Published Apr 14, 2017· Updated Jun 17, 2026
CVE-2017-7870
CVE-2017-7870
Description
LibreOffice before 2017-01-02 has an out-of-bounds write caused by a heap-based buffer overflow related to the tools::Polygon::Insert function in tools/source/generic/poly.cxx.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
38- osv-coords37 versionspkg:rpm/opensuse/libreoffice&distro=openSUSE%20Tumbleweedpkg:rpm/suse/libixion&distro=SUSE%20Linux%20Enterprise%20Desktop%2012%20SP2pkg:rpm/suse/libixion&distro=SUSE%20Linux%20Enterprise%20Desktop%2012%20SP3pkg:rpm/suse/libixion&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP2pkg:rpm/suse/libixion&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP3pkg:rpm/suse/libixion&distro=SUSE%20Linux%20Enterprise%20Workstation%20Extension%2012%20SP2pkg:rpm/suse/libixion&distro=SUSE%20Linux%20Enterprise%20Workstation%20Extension%2012%20SP3pkg:rpm/suse/libmwaw&distro=SUSE%20Linux%20Enterprise%20Desktop%2012%20SP2pkg:rpm/suse/libmwaw&distro=SUSE%20Linux%20Enterprise%20Desktop%2012%20SP3pkg:rpm/suse/libmwaw&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP2pkg:rpm/suse/libmwaw&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP3pkg:rpm/suse/libmwaw&distro=SUSE%20Linux%20Enterprise%20Workstation%20Extension%2012%20SP2pkg:rpm/suse/libmwaw&distro=SUSE%20Linux%20Enterprise%20Workstation%20Extension%2012%20SP3pkg:rpm/suse/liborcus&distro=SUSE%20Linux%20Enterprise%20Desktop%2012%20SP2pkg:rpm/suse/liborcus&distro=SUSE%20Linux%20Enterprise%20Desktop%2012%20SP3pkg:rpm/suse/liborcus&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP2pkg:rpm/suse/liborcus&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP3pkg:rpm/suse/liborcus&distro=SUSE%20Linux%20Enterprise%20Workstation%20Extension%2012%20SP2pkg:rpm/suse/liborcus&distro=SUSE%20Linux%20Enterprise%20Workstation%20Extension%2012%20SP3pkg:rpm/suse/libreoffice&distro=SUSE%20Linux%20Enterprise%20Desktop%2012%20SP2pkg:rpm/suse/libreoffice&distro=SUSE%20Linux%20Enterprise%20Desktop%2012%20SP3pkg:rpm/suse/libreoffice&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP2pkg:rpm/suse/libreoffice&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP3pkg:rpm/suse/libreoffice&distro=SUSE%20Linux%20Enterprise%20Workstation%20Extension%2012%20SP2pkg:rpm/suse/libreoffice&distro=SUSE%20Linux%20Enterprise%20Workstation%20Extension%2012%20SP3pkg:rpm/suse/libstaroffice&distro=SUSE%20Linux%20Enterprise%20Desktop%2012%20SP2pkg:rpm/suse/libstaroffice&distro=SUSE%20Linux%20Enterprise%20Desktop%2012%20SP3pkg:rpm/suse/libstaroffice&distro=SUSE%20Linux%20Enterprise%20Workstation%20Extension%2012%20SP2pkg:rpm/suse/libstaroffice&distro=SUSE%20Linux%20Enterprise%20Workstation%20Extension%2012%20SP3pkg:rpm/suse/libzmf&distro=SUSE%20Linux%20Enterprise%20Desktop%2012%20SP2pkg:rpm/suse/libzmf&distro=SUSE%20Linux%20Enterprise%20Desktop%2012%20SP3pkg:rpm/suse/libzmf&distro=SUSE%20Linux%20Enterprise%20Workstation%20Extension%2012%20SP2pkg:rpm/suse/libzmf&distro=SUSE%20Linux%20Enterprise%20Workstation%20Extension%2012%20SP3pkg:rpm/suse/myspell-dictionaries&distro=SUSE%20Linux%20Enterprise%20Desktop%2012%20SP2pkg:rpm/suse/myspell-dictionaries&distro=SUSE%20Linux%20Enterprise%20Desktop%2012%20SP3pkg:rpm/suse/myspell-dictionaries&distro=SUSE%20Linux%20Enterprise%20Workstation%20Extension%2012%20SP2pkg:rpm/suse/myspell-dictionaries&distro=SUSE%20Linux%20Enterprise%20Workstation%20Extension%2012%20SP3
< 7.1.5.2-3.13+ 36 more
- (no CPE)range: < 7.1.5.2-3.13
- (no CPE)range: < 0.12.1-12.1
- (no CPE)range: < 0.12.1-13.2.1
- (no CPE)range: < 0.12.1-12.1
- (no CPE)range: < 0.12.1-13.2.1
- (no CPE)range: < 0.12.1-12.1
- (no CPE)range: < 0.12.1-13.2.1
- (no CPE)range: < 0.3.11-9.1
- (no CPE)range: < 0.3.11-7.5.1
- (no CPE)range: < 0.3.11-9.1
- (no CPE)range: < 0.3.11-7.5.1
- (no CPE)range: < 0.3.11-9.1
- (no CPE)range: < 0.3.11-7.5.1
- (no CPE)range: < 0.12.1-12.1
- (no CPE)range: < 0.12.1-10.5.1
- (no CPE)range: < 0.12.1-12.1
- (no CPE)range: < 0.12.1-10.5.1
- (no CPE)range: < 0.12.1-12.1
- (no CPE)range: < 0.12.1-10.5.1
- (no CPE)range: < 5.3.3.2-40.5.9
- (no CPE)range: < 5.3.5.2-43.5.4
- (no CPE)range: < 5.3.3.2-40.5.9
- (no CPE)range: < 5.3.5.2-43.5.4
- (no CPE)range: < 5.3.3.2-40.5.9
- (no CPE)range: < 5.3.5.2-43.5.4
- (no CPE)range: < 0.0.3-2.1
- (no CPE)range: < 0.0.3-4.1
- (no CPE)range: < 0.0.3-2.1
- (no CPE)range: < 0.0.3-4.1
- (no CPE)range: < 0.0.1-2.1
- (no CPE)range: < 0.0.1-4.1
- (no CPE)range: < 0.0.1-2.1
- (no CPE)range: < 0.0.1-4.1
- (no CPE)range: < 20170511-15.1
- (no CPE)range: < 20170511-16.2.1
- (no CPE)range: < 20170511-15.1
- (no CPE)range: < 20170511-16.2.1
Patches
Vulnerability mechanics
References
8- github.com/LibreOffice/core/commit/62a97e6a561ce65e88d4c537a1b82c336f012722nvdPatchThird Party Advisory
- www.securityfocus.com/bid/97671nvdThird Party AdvisoryVDB Entry
- bugs.chromium.org/p/oss-fuzz/issues/detailnvdThird Party AdvisoryVDB Entry
- www.debian.org/security/2017/dsa-3837nvd
- www.libreoffice.org/about-us/security/advisories/cve-2017-7870/nvd
- www.securitytracker.com/id/1039029nvd
- access.redhat.com/errata/RHSA-2017:1975nvd
- security.gentoo.org/glsa/201706-28nvd
News mentions
0No linked articles in our index yet.