CVE-2016-10327
Title: CVE-2016-10327 Heap-buffer-overflow in EMF filter
Announced: April 21, 2017
Fixed in: LibreOffice 5.2.5/5.3.0
Description:
Enhanced Metafiles (EMF) can contain bitmap data preceded by a header and a field with in that header which states the offset from the start of the header to the bitmap data. An emf can be crafted to provide an illegal offset which if not tested for validity can trigger a heap buffer overflow.
All users are recommended to upgrade to LibreOffice >= 5.2.5 or >= 5.3.0 which sanity test the offset before use.
References:
CVE-2017-10327
Follow Us