PT-2026-49264 · Document Foundation · Libreoffice
Anthropic
+1
·
Published
2026-06-15
·
Updated
2026-06-15
·
CVE-2026-6045
CVSS v4.0
6.9
Medium
| Vector | AV:L/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
LibreOffice (affected versions not specified)
Description
A heap buffer overflow occurs during the import of EMF+ graphics, which can be embedded in documents. Specifically, the issue arises when importing an EMF+ gradient brush. The software reads the number of gradient blend points from the file to calculate the allocation size; however, this multiplication can overflow. This results in the allocation of a buffer that is too small, which is then filled as if it were larger, leading to data being written past the end of the buffer.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Memory Corruption
Integer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Libreoffice