Описание
A heap use-after-free existed when importing the blank-width characters of an ODF number format. A position value read from the document was not checked against the length of the format-code string, so a malformed number format could be processed against memory outside that string. In fixed versions the position is bounds-checked before use.
| Релиз | Статус | Примечание |
|---|---|---|
| devel | not-affected | 4:26.2.4.2-0ubuntu1 |
| esm-infra/focal | not-affected | code not present |
| jammy | not-affected | code not present |
| noble | released | 4:24.2.7-0ubuntu0.24.04.6 |
| questing | ignored | end of life, was needs-triage |
| resolute | released | 4:26.2.4.2-0ubuntu0.26.04.2 |
| upstream | released | 26.2.3,25.8.7 |
Показывать по
7.3 High
CVSS3
Связанные уязвимости
A heap use-after-free existed when importing the blank-width characters of an ODF number format. A position value read from the document was not checked against the length of the format-code string, so a malformed number format could be processed against memory outside that string. In fixed versions the position is bounds-checked before use.
A heap use-after-free existed when importing the blank-width characters of an ODF number format. A position value read from the document was not checked against the length of the format-code string, so a malformed number format could be processed against memory outside that string. In fixed versions the position is bounds-checked before use.
A heap use-after-free existed when importing the blank-width character ...
A heap use-after-free existed when importing the blank-width characters of an ODF number format. A position value read from the document was not checked against the length of the format-code string, so a malformed number format could be processed against memory outside that string. In fixed versions the position is bounds-checked before use.
7.3 High
CVSS3