CVE-2016-4324 is a high-severity use-after-free vulnerability in LibreOffice versions prior to 5.1.4, allowing remote attackers to execute arbitrary code through specially crafted RTF files. This flaw impacts various distributions including Canonical and Debian Linux, as well as LibreOffice itself. The vulnerability carries a CVSS score of 7.8, indicating a high potential for impact on confidentiality, integrity, and availability, requiring user interaction but with low attack complexity. While there is no known active exploitation or publicly available exploit code in Metasploit or ExploitDB, the vulnerability has garnered some community discussion and media coverage, suggesting awareness within the security community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
8.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:* | ||
<= 5.1.3CPE matchmatch criteria | cpe:2.3:a:libreoffice:libreoffice:*:*:*:*:*:*:*:* | ||
12.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:lts:*:*:* | ||
15.10CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:15.10:*:*:*:*:*:*:* | ||
16.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
libreoffice: Dereference of invalid STL iterator on processing RTF file
Jun 28, 2016Dereference of invalid STL iterator on processing RTF file
Dereference of invalid STL iterator on processing RTF file