AI analysis
LibreOffice Draw has a heap buffer overflow when it imports a PDF stream object. The importer takes the stream length from the object’s own dictionary and does not check it against the number of bytes actually present, so copying the stream reads and writes past the end of the buffer (CWE-125 and CWE-787). A local attacker needs a user to open a crafted PDF (no privileges required); the vendor rates the result as limited confidentiality and integrity impact and high availability impact, with no subsequent-system impact. Anyone running an unfixed LibreOffice Draw build is affected, including installations updated through OS packages such as those covered by Ubuntu USN-8868-1. CISA KEV does not list it and no public proof-of-concept is known, although the CVSS 4.0 vector marks exploit maturity as E:P.
What to do: Install the LibreOffice update from The Document Foundation or your distribution (Ubuntu tracks this in USN-8868-1) so PDF stream lengths are clamped to the bytes actually read. Until then, do not open untrusted PDFs in LibreOffice Draw. Confirm the installed package is the patched build named in your vendor advisory; exact fixed version numbers were not included in the supplied CVE data.
Affected
| The Document Foundation LibreOffice Draw (PDF import) | — |
Estimated exposure
massOn the order of 100 million LibreOffice installations (vulnerable-version share unknown) — Estimate from LibreOffice’s public deployment pattern as a mainstream free office suite (Document Foundation has cited on the order of 200 million users, and it is commonly bundled with Linux distributions and also used on Windows and…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
LibreOffice Draw can import PDF documents. A heap buffer overflow existed when importing a stream object. The length of the stream was taken from the object's own dictionary and was not checked against the number of bytes actually present, so copying the stream read and wrote past the end of the buffer holding it. In fixed versions the declared length is clamped to the bytes actually read.