FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2005-2972

This CVE name corresponds to:

Entered Topic
2006-02-20 abiword, koffice -- stack based buffer overflow vulnerabilities

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2005-2972
Phase Assigned(20050919)

Description

Multiple stack-based buffer overflows in the RTF import feature in AbiWord before 2.2.11 allow user-assisted attackers to execute arbitrary code via an RTF file with long identifiers, which are not properly handled in the (1) ParseLevelText, (2) getCharsInsideBrace, (3) HandleLists, (4) or (5) HandleAbiLists functions in ie_imp_RTF.cpp, a different vulnerability than CVE-2005-2964.

References

Source Reference
MISC http://scary.beasts.org/security/CESA-2005-006.txt
MISC http://www.mail-archive.com/debian-bugs-rc@lists.debian.org/msg28251.html
CONFIRM http://www.abisource.com/changelogs/2.2.11.phtml
DEBIAN DSA-894
FEDORA FEDORA-2005-989
GENTOO GLSA-200510-17
UBUNTU USN-203-1
BID 15096
VUPEN ADV-2005-2086
OSVDB 20015
SECUNIA 17199
SECUNIA 17200
SECUNIA 17213
SECUNIA 17264
SECUNIA 17551