Crash while importing malformed .rtf file. According to valgrind (log attached) there are several invalid writes, including near malloc'd block. Seems to be potentially exploitable.
Tested on Debian Stable.
Created attachment 109705 [details]
Created attachment 109706 [details]
Did you really report this bug against version 3.5.4? This version is very old and not maintained anymore. If it is the case, did you check if the problem is present in current stable versions and in master? If the problem is not present in the current versions, I fear we should close this bug report as WontFix.
Set status to NEEDINFO. Please set it back to UNCONFIRMED once you have provided requested informations. Thank you for your understanding.
Best regards. JBF
No crash on master, FWIW.
http://cgit.freedesktop.org/libreoffice/core/commit/?h=libreoffice-4-3 commit bot seems busted, so adding this manually
*** Bug 86448 has been marked as a duplicate of this bug. ***
Bah, I meant http://cgit.freedesktop.org/libreoffice/core/commit/?h=libreoffice-4-3&id=b4840d3632e4404bee4bd192a7db916cbad3a401
This might be the possible sol to the .rtf problem, but I'm not completely sure.
Moving to UNCONFIRMED by a spammer. putting it back to RESOLVED FIXED