Gentoo Archives: gentoo-announce

From: Sune Kloppenborg Jeppesen <jaervosz@g.o>
To: gentoo-announce@l.g.o
Cc: bugtraq@×××××××××××××.com, full-disclosure@××××××××××××××.uk, security-alerts@×××××××××××××.com
Subject: [gentoo-announce] [ GLSA 200510-12 ] KOffice, KWord: RTF import buffer overflow
Date: Fri, 14 Oct 2005 07:35:46
Message-Id: 200510140730.07263.jaervosz@gentoo.org
1 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
2 Gentoo Linux Security Advisory GLSA 200510-12
3 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
4 http://security.gentoo.org/
5 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
6
7 Severity: Normal
8 Title: KOffice, KWord: RTF import buffer overflow
9 Date: October 14, 2005
10 Bugs: #108411
11 ID: 200510-12
12
13 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
14
15 Synopsis
16 ========
17
18 KOffice and KWord are vulnerable to a buffer overflow in the RTF
19 importer, potentially resulting in the execution of arbitrary code.
20
21 Background
22 ==========
23
24 KOffice is an integrated office suite for KDE. KWord is the KOffice
25 word processor.
26
27 Affected packages
28 =================
29
30 -------------------------------------------------------------------
31 Package / Vulnerable / Unaffected
32 -------------------------------------------------------------------
33 1 app-office/koffice < 1.4.1-r1 >= 1.4.1-r1
34 2 app-office/kword < 1.4.1-r1 >= 1.4.1-r1
35 -------------------------------------------------------------------
36 2 affected packages on all of their supported architectures.
37 -------------------------------------------------------------------
38
39 Description
40 ===========
41
42 Chris Evans discovered that the KWord RTF importer was vulnerable to a
43 heap-based buffer overflow.
44
45 Impact
46 ======
47
48 An attacker could entice a user to open a specially-crafted RTF file,
49 potentially resulting in the execution of arbitrary code with the
50 rights of the user running the affected application.
51
52 Workaround
53 ==========
54
55 There is no known workaround at this time.
56
57 Resolution
58 ==========
59
60 All KOffice users should upgrade to the latest version:
61
62 # emerge --sync
63 # emerge --ask --oneshot --verbose ">=app-office/koffice-1.4.1-r1"
64
65 All KWord users should upgrade to the latest version:
66
67 # emerge --sync
68 # emerge --ask --oneshot --verbose ">=app-office/kword-1.4.1-r1"
69
70 References
71 ==========
72
73 [ 1 ] CAN-2005-2971
74 http://cve.mitre.org/cgi-bin/cvename.cgi?name=2005-2971
75 [ 2 ] KDE Security Advisory: KWord RTF import buffer overflow
76 http://www.kde.org/info/security/advisory-20051011-1.txt
77
78 Availability
79 ============
80
81 This GLSA and any updates to it are available for viewing at
82 the Gentoo Security Website:
83
84 http://security.gentoo.org/glsa/glsa-200510-12.xml
85
86 Concerns?
87 =========
88
89 Security is a primary focus of Gentoo Linux and ensuring the
90 confidentiality and security of our users machines is of utmost
91 importance to us. Any security concerns should be addressed to
92 security@g.o or alternatively, you may file a bug at
93 http://bugs.gentoo.org.
94
95 License
96 =======
97
98 Copyright 2005 Gentoo Foundation, Inc; referenced text
99 belongs to its owner(s).
100
101 The contents of this document are licensed under the
102 Creative Commons - Attribution / Share Alike license.
103
104 http://creativecommons.org/licenses/by-sa/2.0