Impact
GNU libextractor contains a stack‑based buffer overflow in the process_star_office function when handling OLE2 stream data. An attacker can craft a malicious StarOffice document that forces the library to allocate a variable‑length stack array up to 4 MB, causing the targeted application to crash. The described effect is a denial of service through application termination. The description does not explicitly state arbitrary code execution, so the immediate impact is limited to crashing, though a corrupted stack could potentially lead to further exploitation in untested scenarios.
Affected Systems
The vulnerability affects the GNU libextractor library prior to version 1.15. All installations of libextractor older than 1.15 are potentially impacted. No specific sub‑version details are provided beyond the pre‑1.15 threshold.
Risk and Exploitability
The CVSS score of 8.7 classifies the issue as high severity. EPSS score of <1% indicates a very low probability of exploitation, and the vulnerability is not listed in CISA KEV. The likely attack vector, inferred from the description, involves the delivery of a crafted StarOffice document to a system that uses libextractor to extract metadata. This could occur via shared network drives, email attachments, or other file‑exchange mechanisms, as inferred. While no proof of remote code execution is provided, the stack overflow could potentially be leveraged by attackers in environments where the offending application runs with elevated privileges. The risk remains high for systems that routinely process untrusted OpenOffice/StarOffice files.
OpenCVE Enrichment