CVE-2015-1774

Title: CVE-2015-1774 Out of bounds write in HWP file filter

Announced: April  27, 2015

Fixed in: LibreOffice 4.3.7/4.4.2

Description:

Certain crafted HWP documents can allow attackers to cause a denial of service or possibly the execution of arbitrary code by writing past the end of buffers.


All users are recommended to upgrade to LibreOffice 4.3.7 or 4.4.2.

Thanks to the researchers working with VeriSign iDefense Labs for discovering this flaw.

References:

    CVE-2015-1774