Описание
LibreOffice can import documents in the OOXML format (DOCX). A heap buffer overflow existed when replaying deferred parser events for a text box element. A handler object was assumed to be of one type and written to at that type's field layout, but it could be a smaller object, so the write landed past the end of the allocation. In fixed versions the type is checked before the write.
A flaw was found in LibreOffice. This vulnerability, a heap buffer overflow, occurs when processing specially crafted OOXML (Office Open XML) documents. An attacker could create a malicious document that, when opened, causes a write beyond the intended memory boundary during the replaying of deferred parser events for text box elements. This could lead to a denial of service, making the application unavailable.
Отчет
This Moderate impact flaw in LibreOffice stems from a heap buffer overflow when handling specially crafted OOXML documents. Successful exploitation requires user interaction, where a victim must open a malicious document, resulting in a denial of service. This issue primarily affects application availability and does not facilitate arbitrary code execution or data exfiltration.
Меры по смягчению последствий
To mitigate this issue, users should exercise caution when opening untrusted or suspicious OOXML documents. Avoiding the opening of such documents from unknown sources can prevent the exploitation of this vulnerability. If possible, process untrusted documents in a sandboxed environment.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 6 | libreoffice | Out of support scope | ||
| Red Hat Enterprise Linux 7 | libreoffice | Out of support scope | ||
| Red Hat Enterprise Linux 8 | libreoffice | Fix deferred | ||
| Red Hat Enterprise Linux 9 | libreoffice | Fix deferred |
Показывать по
Дополнительная информация
Статус:
EPSS
5 Medium
CVSS3
Связанные уязвимости
LibreOffice can import documents in the OOXML format (DOCX). A heap buffer overflow existed when replaying deferred parser events for a text box element. A handler object was assumed to be of one type and written to at that type's field layout, but it could be a smaller object, so the write landed past the end of the allocation. In fixed versions the type is checked before the write.
LibreOffice can import documents in the OOXML format (DOCX). A heap buffer overflow existed when replaying deferred parser events for a text box element. A handler object was assumed to be of one type and written to at that type's field layout, but it could be a smaller object, so the write landed past the end of the allocation. In fixed versions the type is checked before the write.
LibreOffice can import documents in the OOXML format (DOCX). A heap bu ...
LibreOffice can import documents in the OOXML format (DOCX). A heap buffer overflow existed when replaying deferred parser events for a text box element. A handler object was assumed to be of one type and written to at that type's field layout, but it could be a smaller object, so the write landed past the end of the allocation. In fixed versions the type is checked before the write.
Уязвимость пакета офисных программ LibreOffice, связанная с переполнением буфера в динамической памяти, позволяющая нарушителю вызвать отказ в обслуживании
EPSS
5 Medium
CVSS3