Talos is disclosing the presence of a Use After Free vulnerability within the RTF parsing of LibreOffice. The vulnerability lies in the parsing of documents containing both stylesheet and superscript tokens. A specially crafted RTF document containing a stylesheet or superscript element causes LibreOffice to access an invalid pointer referencing previously used memory on the heap. By carefully manipulating the contents of the heap, this vulnerability can be able to be used to execute arbitrary code. This vulnerability requires user interaction to open the file.”]
Source: https://blog.talosintelligence.com/2016/06/vulnerability-spotlight-libreoffice-rtf.html