|
OpenOffice.org contains an integer overflow condition that is triggered as user-supplied input is not properly validated when parsing EMR_STRETCHBLT records in EMF files. With a specially crafted document containing an embedded EMF file, a context-dependent attacker can cause a buffer overflow, resulting in a denial of service or potentially execution of arbitrary code.
|