Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 22 Sep 2026 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | LibreOffice Draw can import PDF documents. A heap buffer overflow existed when importing an encrypted document. The length of the decryption key was taken from the document's own encryption dictionary and was used to fill a fixed size key buffer without being checked against it, so a length larger than that buffer wrote past its end. In fixed versions a declared key length larger than the buffer is rejected. | |
| Title | Heap buffer overflow in PDF import encryption handling | |
| Weaknesses | CWE-787 | |
| References |
| |
| Metrics |
cvssV4_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: Document Fdn.
Published:
Updated: 2026-09-22T12:27:46.334Z
Reserved: 2026-07-16T08:17:05.512Z
Link: CVE-2026-63273
No data.
Status : Received
Published: 2026-09-22T12:17:13.007
Modified: 2026-09-22T12:17:13.007
Link: CVE-2026-63273
No data.
OpenCVE Enrichment
Updated: 2026-09-22T12:30:07Z