Impact
LibreOffice’s CFF font reader contains a stack buffer overflow that is triggered when the glyph hint count is incorrectly validated. A glyph that declares more hints than the array can accommodate writes past the array bounds, potentially corrupting stack memory. While the data does not explicitly state the precise consequences, such an overflow could lead to a crash or, depending on the context, arbitrary code execution.
Affected Systems
The vulnerability affects The Document Foundation’s LibreOffice suite when processing documents that embed CFF fonts. Specific vulnerable releases are not enumerated in the input, but the flaw exists in any LibreOffice version that includes the unpatched CFF font hint reader. Users should verify whether their installed LibreOffice version contains the patch described in the advisory linked in the references.
Risk and Exploitability
The CVSS score of 5.4 indicates a moderate severity. EPSS is not available, and the issue is not listed in the CISA KEV catalog, suggesting it is not a widely exploited or immediately dangerous vulnerability. Exploitation would require local access to a document containing a malicious CFF font and the ability to open that document in LibreOffice, making the attack vector non‑remote and dependent on user action.
OpenCVE Enrichment