First published: Mon Nov 16 2020(Updated: )
libreoffice-7.0.2.2+ Impress aborts with a stack smashing error when provided a crafted .odp presentation file, on GNOME with the "scale" Display setting set to 175%. The issue is likely due to a problem in the cairo dependency. This could be related to [1] and is likely caused by [2] 1. <a href="https://gitlab.freedesktop.org/pixman/pixman/-/issues/9">https://gitlab.freedesktop.org/pixman/pixman/-/issues/9</a> 2. <a href="https://gitlab.freedesktop.org/cairo/cairo/-/commit/c986a7310bb06582b7d8a566d5f007ba4e5e75bf">https://gitlab.freedesktop.org/cairo/cairo/-/commit/c986a7310bb06582b7d8a566d5f007ba4e5e75bf</a>
Affected Software | Affected Version | How to fix |
---|---|---|
LibreOffice Draw |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of REDHAT-BUG-1898396 is critical due to potential application crashes when processing malicious .odp files.
To fix REDHAT-BUG-1898396, update to the latest version of LibreOffice that includes security patches addressing this vulnerability.
ROOT-Bug-1898396 affects LibreOffice on systems running GNOME with a display scale setting of 175%.
REDHAT-BUG-1898396 is a stack smashing vulnerability that leads to application crashes.
Yes, user data can be at risk if a crafted .odp presentation file is opened, which may lead to unauthorized access or exploitation.