Libreoffice RTF parser Arbitrary Code Execution Vulnerability (CVE-2016-4324)
Libreoffice RTF parser Arbitrary Code Execution Vulnerability (CVE-2016-4324)
Release date:
Updated on:
Affected Systems:
Libreoffice <5.1.4
Description:
CVE (CAN) ID: CVE-2016-4324
LibreOffice is a suite that can be executed on various platforms and is compatible with other major office software.
The libreoffice RTF parser does not enter the input filter, which can cause attackers to execute arbitrary code through malformed documents.
<* Source: Aleksandar Nikolic
*>
Suggestion:
Vendor patch:
Libreoffice
-----------
The vendor has released the upgrade patch LibreOffice> = 5.1.4 to fix this security problem. Please download it from the vendor's homepage:
Https://www.libreoffice.org/about-us/security/advisories/cve-2016-4324/
This article permanently updates the link address: