VYPR

Libextractor Ole2 Rce

by Haitam Lazaar

CVEs (1)

  • CVE-2026-91752HigSep 15, 2026
    risk 0.49cvss 7.5epss

    GNU libextractor before 1.15 contains a stack-based buffer overflow vulnerability in the process_star_office function that sizes a variable-length stack array from attacker-controlled OLE2 stream data. Attackers can craft malicious StarOffice documents that allocate up to 4 MB…