Calligra Words Buffer Overflow in MS Word Filter
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
calligra (Ubuntu) |
Invalid
|
Critical
|
Unassigned | ||
Lucid |
Invalid
|
Undecided
|
Unassigned | ||
Natty |
Invalid
|
Undecided
|
Unassigned | ||
Oneiric |
Invalid
|
Undecided
|
Unassigned | ||
Precise |
Invalid
|
Medium
|
Marc Deslauriers | ||
Quantal |
Invalid
|
Critical
|
Unassigned | ||
koffice (Ubuntu) |
Invalid
|
Undecided
|
Unassigned | ||
Lucid |
Invalid
|
Undecided
|
Unassigned | ||
Natty |
Invalid
|
Undecided
|
Unassigned | ||
Oneiric |
Invalid
|
Medium
|
Marc Deslauriers | ||
Precise |
Invalid
|
Medium
|
Marc Deslauriers | ||
Quantal |
Invalid
|
Undecided
|
Unassigned | ||
wv2 (Ubuntu) |
Invalid
|
Critical
|
Unassigned | ||
Lucid |
Invalid
|
Undecided
|
Unassigned | ||
Natty |
Invalid
|
Undecided
|
Unassigned | ||
Oneiric |
Invalid
|
Undecided
|
Unassigned | ||
Precise |
Invalid
|
High
|
Unassigned | ||
Quantal |
Invalid
|
Critical
|
Unassigned |
Bug Description
This is from the private KDE packagers email list. It says the information is public, but I don't find any reference to Calligra in the article it mentions - http://
Hello,
A security vulnerability has been found in Calligra Words. Affected versions
are all below 2.5.0 (2.5.0 will have the fix once tagged in a couple of
hours).
It is already public information, you can find it in the "Exploring the NFC
Attack Surface" article by Charlie Miller of Accuvant.
You have in attachement the patch to fix the issue. There is no CVE number
since we could not find help from <email address hidden> on that front, so if you
need/want one, and would be available to help us with that, please contact us.
--
Cyrille Berger Skott
Changed in wv2 (Ubuntu Precise): | |
importance: | Undecided → High |
status: | New → Confirmed |
Changed in calligra (Ubuntu Precise): | |
assignee: | nobody → Marc Deslauriers (mdeslaur) |
importance: | Critical → Medium |
Changed in koffice (Ubuntu Oneiric): | |
assignee: | nobody → Marc Deslauriers (mdeslaur) |
importance: | Undecided → Medium |
status: | New → Confirmed |
Changed in koffice (Ubuntu Precise): | |
assignee: | nobody → Marc Deslauriers (mdeslaur) |
importance: | Undecided → Medium |
status: | Invalid → Confirmed |
Changed in wv2 (Ubuntu Lucid): | |
status: | New → Incomplete |
Changed in wv2 (Ubuntu Natty): | |
status: | New → Incomplete |
Changed in wv2 (Ubuntu Oneiric): | |
status: | New → Incomplete |
Changed in wv2 (Ubuntu Precise): | |
status: | Confirmed → Incomplete |
Changed in wv2 (Ubuntu Quantal): | |
status: | New → Incomplete |
Found it on page 40. The bug is in an embedded code copy of wv2. It appears our wv2 package is likely affected as well.