Calligra: User-assisted execution of arbitrary code
1.
Gentoo Linux Security Advisory
Version Information
| Advisory Reference |
GLSA 201209-10 / calligra |
| Release Date |
September 25, 2012 |
| Latest Revision |
September 25, 2012: 1 |
| Impact |
normal |
| Exploitable |
remote |
| Package |
Vulnerable versions |
Unaffected versions |
Architecture(s) |
| app-office/calligra |
<
2.4.3-r1 |
>=
2.4.3-r1 |
All supported architectures
|
Related bugreports:
#428890
Synopsis
A buffer overflow vulnerability in Calligra could result in the
execution of arbitrary code.
2.
Impact Information
Background
Calligra is an office suite by KDE.
Description
An error in the read() function in styles.cpp could cause a heap-based
buffer overflow.
Impact
A remote attacker could entice a user to open a specially crafted ODF
file, possibly resulting in execution of arbitrary code with the
privileges of the process or a Denial of Service condition.
3.
Resolution Information
Workaround
There is no known workaround at this time.
Resolution
All Calligra users should upgrade to the latest version:
Code Listing 3.1: Resolution |
# emerge --sync
# emerge --ask --oneshot --verbose ">=app-office/calligra-2.4.3-r1"
|
4.
References
|