Heap-based buffer overflow in the ole_info_read_metabat function in Gnome Structured File library (libgsf) 1.14.0, and other versions before 1.14.2, allows context-dependent attackers to execute arbitrary code via a large num_metabat value in an OLE document, which causes the ole_init_info function to allocate insufficient memory.
CVSS Details
- CVSS 3.1 Base Score: 7.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade libgsf | Jul 30, 2024 | Nov 30, 2006 |
| Gentoo Linux | — | Upgrade gnome-extra/libgsf. | Oct 30, 2017 | Nov 30, 2006 |
| Suse | — | Upgrade libgsf | Feb 17, 2015 | Nov 30, 2006 |
| Ubuntu | — | Upgrade libgsf-1-114Upgrade libgsf-1Upgrade libgsf-1-113 | Nov 8, 2024 | Nov 30, 2006 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub