https://bugs.documentfoundation.org/show_bug.cgi?id=98136

--- Comment #4 from Armin Le Grand (CIB) <[email protected]> ---
Seems to happen at preparing the preview for slide 6 (may be reduced to that
slide, though). Crash is in SvMemoryStream::ReAllocateMemory which gets a
negative value as diff. That may be allowed, but leads to a nNewSize value of
4294934350 (0xffff7f4e) which is probably too big.
All this comes from reading a Metafile and there a a VersionCompat which gets
created and reads in a size of 0xffff0000 which it tries to seek forward over.
The action Type read is 1753 and probably not a VersionCompat, but that is of
course the default at MetaAction::ReadMetaAction.
Ths looks like a malformed metafile, checking the presentation file contents
directly...

-- 
You are receiving this mail because:
You are the assignee for the bug.
_______________________________________________
Libreoffice-bugs mailing list
[email protected]
https://lists.freedesktop.org/mailman/listinfo/libreoffice-bugs

Reply via email to