LibreOffice before 2017-03-11 has an out-of-bounds write caused by a heap-based buffer overflow in the SVMConverter::ImplConvertFromSVM1 function in vcl/source/gdi/svmconverter.cxx.
[
{
"deprecated": false,
"id": "CVE-2017-7856-4acdecd9",
"source": "https://github.com/libreoffice/core/commit/28e61b634353110445e334ccaa415d7fb6629d62",
"digest": {
"function_hash": "298204384063460422800894264659505851315",
"length": 18329.0
},
"target": {
"function": "SVMConverter::ImplConvertFromSVM1",
"file": "vcl/source/gdi/svmconverter.cxx"
},
"signature_type": "Function",
"signature_version": "v1"
},
{
"deprecated": false,
"id": "CVE-2017-7856-caaf43c2",
"source": "https://github.com/libreoffice/core/commit/28e61b634353110445e334ccaa415d7fb6629d62",
"digest": {
"line_hashes": [
"56997574373070255410130733878905353393",
"201536209379238536522222923938150462503",
"221828152900981007123820303299634245832",
"86529089122140294639030571344540798397"
],
"threshold": 0.9
},
"target": {
"file": "vcl/source/gdi/svmconverter.cxx"
},
"signature_type": "Line",
"signature_version": "v1"
}
]