CVE-2017-11110: High severity catdoc vulnerability
Published Jul 8, 2017
·Updated
The oleinit function in ole.c in catdoc 0.95 allows remote attackers to cause a denial of service (heap-based buffer underflow and application crash) or possibly have unspecified other impact via a crafted file, i.e., data is written to memory addresses before the beginning of the tmpBuf buffer.
Affected Software
1 affected component
Fossies Catdoc=0.95
Event History
Jul 8, 2017
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-11110?
CVE-2017-11110 has a medium severity rating, potentially resulting in denial of service.
2
How do I fix CVE-2017-11110?
To fix CVE-2017-11110, upgrade to a newer version of Catdoc that addresses this vulnerability.
3
What impact does CVE-2017-11110 have on affected systems?
CVE-2017-11110 can lead to a heap-based buffer underflow, causing application crashes and possible other impacts.
4
Is my software vulnerable if I use Catdoc version 0.95?
Yes, Catdoc version 0.95 is vulnerable to CVE-2017-11110 and should be updated.
5
Can CVE-2017-11110 be exploited remotely?
Yes, CVE-2017-11110 can be exploited by remote attackers via crafted files.