CVE-2012-3456

Heap-based buffer overflow in the read function in filters/words/msword-odf/wv2/src/styles.cpp in the Microsoft import filter in Calligra 2.4.3 and earlier allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted ODF style in an ODF document.  NOTE: this is the same vulnerability as CVE-2012-3455, but it was SPLIT by the CNA even though Calligra and KOffice share the same codebase.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:P/I:P/A:P
redhatCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 97%
VendorProductVersion
calligracalligra
𝑥
≤ 2.4.3
calligracalligra
2.4
calligracalligra
2.4:beta2
calligracalligra
2.4:beta3
calligracalligra
2.4:beta4
calligracalligra
2.4:beta6
calligracalligra
2.4:beta7
calligracalligra
2.4:rc2
calligracalligra
2.4.1
calligracalligra
2.4.2
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
calligra
bullseye
1:3.2.1+dfsg-2
fixed
squeeze
no-dsa
bookworm
1:3.2.1+dfsg-6
fixed
sid
1:3.2.1+dfsg-9
fixed
trixie
1:3.2.1+dfsg-9
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
calligra
precise
Fixed 1:2.4.0-0ubuntu2.1
released
oneiric
dne
natty
dne
lucid
dne
hardy
dne
References