PT-2026-91773 · Gnu · Libextractor
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
GNU libextractor versions prior to 1.15
Description
A stack-based buffer overflow occurs in the
process star office() function. The issue arises when the function determines the size of a variable-length stack array using attacker-controlled OLE2 stream data. An attacker can create malicious StarOffice documents that allocate up to 4 MB on the stack, leading to a stack overflow and causing any application extracting metadata from the document to crash.Recommendations
Update to version 1.15 or later.
Exploit
Fix
RCE
DoS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Libextractor