7.5
CVSSv2

CVE-2005-2971

Published: 20/10/2005 Updated: 03/10/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Heap-based buffer overflow in the KWord RTF importer for KOffice 1.2.0 up to and including 1.4.1 allows remote malicious users to execute arbitrary code via a crafted RTF file.

Vulnerable Product Search on Vulmon Subscribe to Product

kde koffice 1.3.3

kde koffice 1.3.4

kde koffice 1.3.1

kde koffice 1.3.2

kde koffice 1.4

kde koffice 1.4.1

kde koffice 1.2

kde koffice 1.3.5

kde koffice 1.3_beta1

kde koffice 1.2.1

kde koffice 1.3

kde koffice 1.3_beta2

kde koffice 1.3_beta3

Vendor Advisories

Chris Evans discovered a buffer overflow in the RTF import module of KOffice By tricking a user into opening a specially-crafted RTF file, an attacker could exploit this to execute arbitrary code with the privileges of the AbiWord user ...
Chris Evans discovered a buffer overflow in the RTF importer of kword, a word processor for the KDE Office Suite that can lead to the execution of arbitrary code The old stable distribution (woody) does not contain a kword package For the stable distribution (sarge) this problem has been fixed in version 135-4sarge1 For the unstable distribu ...