Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-8356

Опубликовано: 15 июн. 2026
Источник: redhat
CVSS3: 5.5

Описание

LibreOffice can import presentations in the legacy binary PPT format. A stack buffer overflow existed when importing a colour-replacement record. Two fixed-size colour tables were filled from the file, but the write position was not reset between the two passes over the record, so a file whose combined colour counts exceeded the table size wrote past the end of the tables on the stack. In fixed versions the unused second pass is no longer read into those tables.

A flaw was found in LibreOffice. This vulnerability, a stack buffer overflow, occurs when processing specially crafted legacy PowerPoint (PPT) files. An attacker could exploit this by convincing a user to open a malicious document, which may lead to a denial of service (DoS) due to the application crashing. This primarily affects desktop users who handle untrusted files.

Отчет

This Moderate impact denial of service vulnerability in LibreOffice is due to a stack buffer overflow when parsing specially crafted legacy PowerPoint (PPT) files. Successful exploitation requires user interaction, as an attacker must persuade a user to open a malicious document. The flaw primarily affects desktop users who process untrusted files.

Меры по смягчению последствий

Users should exercise caution when opening untrusted or suspicious legacy PowerPoint (PPT) files. Avoid opening documents from unknown sources to prevent potential denial of service attacks. If possible, process untrusted documents in a sandboxed environment.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6libreofficeOut of support scope
Red Hat Enterprise Linux 7libreofficeOut of support scope
Red Hat Enterprise Linux 8libreofficeFix deferred
Red Hat Enterprise Linux 9libreofficeFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-131
https://bugzilla.redhat.com/show_bug.cgi?id=2488961libreoffice: LibreOffice: Denial of Service via a specially crafted PPT file

5.5 Medium

CVSS3

Связанные уязвимости

ubuntu
около 2 месяцев назад

LibreOffice can import presentations in the legacy binary PPT format. A stack buffer overflow existed when importing a colour-replacement record. Two fixed-size colour tables were filled from the file, but the write position was not reset between the two passes over the record, so a file whose combined colour counts exceeded the table size wrote past the end of the tables on the stack. In fixed versions the unused second pass is no longer read into those tables.

nvd
около 2 месяцев назад

LibreOffice can import presentations in the legacy binary PPT format. A stack buffer overflow existed when importing a colour-replacement record. Two fixed-size colour tables were filled from the file, but the write position was not reset between the two passes over the record, so a file whose combined colour counts exceeded the table size wrote past the end of the tables on the stack. In fixed versions the unused second pass is no longer read into those tables.

debian
около 2 месяцев назад

LibreOffice can import presentations in the legacy binary PPT format. ...

github
около 2 месяцев назад

LibreOffice can import presentations in the legacy binary PPT format. A stack buffer overflow existed when importing a colour-replacement record. Two fixed-size colour tables were filled from the file, but the write position was not reset between the two passes over the record, so a file whose combined colour counts exceeded the table size wrote past the end of the tables on the stack. In fixed versions the unused second pass is no longer read into those tables.

CVSS3: 5.5
fstec
около 2 месяцев назад

Уязвимость пакета офисных программ LibreOffice, связанная с переполнением буфера в стеке, позволяющая нарушителю вызвать отказ в обслуживании

5.5 Medium

CVSS3