AI analysis
LibreOffice Draw has a heap buffer overflow (CWE-787) when importing an encrypted PDF. The importer takes the decryption-key length from the document’s own encryption dictionary and uses it to fill a fixed-size key buffer without checking that length, so a declared length larger than the buffer writes past its end. A person must open or import a crafted encrypted PDF (local, user interaction); the overflow can crash Draw and, as scored, has limited confidentiality and integrity impact with high availability impact on the vulnerable component. Anyone using an unfixed LibreOffice that includes Draw is affected; fixed versions reject an oversized declared key length. No public proof of concept is listed and the issue is not in the CISA KEV catalog, although the published CVSS 4.0 vector sets exploit maturity to P and scores the flaw 5.4 (medium).
What to do: Update LibreOffice to a fixed release that rejects an encryption-dictionary key length larger than the fixed key buffer; use the Document Foundation advisory and Ubuntu USN-8868-1 for the corrected packages rather than assuming a version number. Until patched, do not import or open untrusted encrypted PDFs in LibreOffice Draw.
Affected
| The Document Foundation LibreOffice Draw | — |
Estimated exposure
masson the order of 100 million LibreOffice users (Draw ships with the suite) — LibreOffice is a mainstream free office suite and Draw is bundled with it; The Document Foundation has publicly described a user base on the order of hundreds of millions, so unfixed installations plausibly exceed one million even though…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
LibreOffice Draw can import PDF documents. A heap buffer overflow existed when importing an encrypted document. The length of the decryption key was taken from the document's own encryption dictionary and was used to fill a fixed size key buffer without being checked against it, so a length larger than that buffer wrote past its end. In fixed versions a declared key length larger than the buffer is rejected.