漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Heap buffer overflow in OOXML text box element import
Vulnerability Description
LibreOffice can import documents in the OOXML format (DOCX). A heap buffer overflow existed when replaying deferred parser events for a text box element. A handler object was assumed to be of one type and written to at that type's field layout, but it could be a smaller object, so the write landed past the end of the allocation. In fixed versions the type is checked before the write.
CVSS Information
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N/E:P
Vulnerability Type
跨界内存写
Vulnerability Title
The Document Foundation LibreOffice 缓冲区错误漏洞
Vulnerability Description
The Document Foundation LibreOffice是The Document Foundation的办公套件。 The Document Foundation LibreOffice存在缓冲区错误漏洞,该漏洞源于导入OOXML格式文档时堆缓冲区溢出,在重放文本框元素的延迟解析器事件时,处理程序对象类型假设错误导致写入超出分配内存边界。
CVSS Information
N/A
Vulnerability Type
N/A