A buffer overflow vulnerability in Calligra could result in the execution of arbitrary code.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 201209-10 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: Calligra: User-assisted execution of arbitrary code Date: September 25, 2012 Bugs: #428890 ID: 201209-10 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= A buffer overflow vulnerability in Calligra could result in the execution of arbitrary code. Background ========= Calligra is an office suite by KDE. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 app-office/calligra < 2.4.3-r1 > = 2.4.3-r1 Description ========== An error in the read() function in styles.cpp could cause a heap-based buffer overflow. Impact ===== A remote attacker could entice a user to open a specially crafted ODF file, possibly resulting in execution of arbitrary code with the privileges of the process or a Denial of Service condition. Workaround ========= There is no known workaround at this time. Resolution ========= All Calligra users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =app-office/calligra-2.4.3-r1" References ========= [ 1 ] CVE-2012-3456 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-3456 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/201209-10 Concerns? ======== Security is a primary focus of GentooLinux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to
Calligra could be made to crash or run programs as your login if it opened a specially crafted file.. =========================================================================Ubuntu Security Notice USN-1525-1 August 09, 2012 calligra vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 12.04 LTS Summary: Calligra could be made to crash or run programs as your login if it opened a specially crafted file. Software Description: - calligra: integrated work applications suite Details: It was discovered that Calligra incorrectly handled certain malformed MS Word documents. If a user or automated system were tricked into opening a crafted MS Word file, an attacker could cause a denial of service or execute arbitrary code with privileges of the user invoking the program. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 12.04 LTS: calligra 1:2.4.0-0ubuntu2.1 After a standard system update you need to restart Calligra to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-1525-1 CVE-2012-3456 Package Information: https://launchpad.net/ubuntu/+source/calligra/1:2.4.0-0ubuntu2.1 . A flaw in Calligra posed threats to user safety. Upgrade your Ubuntu system to bolster defenses and reduce potential intrusions.. calligra exploit, denial of service, software risk. . Severity: Important. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.