Vulnerability Name: | CVE-2005-2972 (CCN-22454) | ||||||||
Assigned: | 2005-09-29 | ||||||||
Published: | 2005-09-29 | ||||||||
Updated: | 2018-10-03 | ||||||||
Summary: | Multiple stack-based buffer overflows in the RTF import feature in AbiWord before 2.2.11 allow user-assisted attackers to execute arbitrary code via an RTF file with long identifiers, which are not properly handled in the (1) ParseLevelText, (2) getCharsInsideBrace, (3) HandleLists, (4) or (5) HandleAbiLists functions in ie_imp_RTF.cpp, a different vulnerability than CVE-2005-2964. | ||||||||
CVSS v3 Severity: | 7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||
CVSS v2 Severity: | 5.1 Medium (CVSS v2 Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P)
| ||||||||
Vulnerability Type: | CWE-119 | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: MITRE Type: CNA CVE-2005-2964 Source: MITRE Type: CNA CVE-2005-2972 Source: MISC Type: Exploit, Vendor Advisory http://scary.beasts.org/security/CESA-2005-006.txt Source: CCN Type: SA16982 AbiWord RTF Importer Buffer Overflow Vulnerability Source: CCN Type: SA17199 AbiWord RTF Importer Buffer Overflow Vulnerabilities Source: SECUNIA Type: Vendor Advisory 17199 Source: SECUNIA Type: Vendor Advisory 17200 Source: SECUNIA Type: Vendor Advisory 17213 Source: SECUNIA Type: Vendor Advisory 17264 Source: SECUNIA Type: Vendor Advisory 17551 Source: CCN Type: SECTRACK ID: 1014982 AbiWord Buffer Overflow in RTF Importer May Let Remote Users Execute Arbitrary Code Source: CCN Type: AbiWord Web site AbiWord Source: CONFIRM Type: UNKNOWN http://www.abisource.com/changelogs/2.2.11.phtml Source: DEBIAN Type: UNKNOWN DSA-894 Source: DEBIAN Type: DSA-894 abiword -- buffer overflows Source: CCN Type: GLSA-200509-20 AbiWord: RTF import stack-based buffer overflow Source: CCN Type: GLSA-200510-17 AbiWord: New RTF import buffer overflows Source: GENTOO Type: Patch, Vendor Advisory GLSA-200510-17 Source: MISC Type: Vendor Advisory http://www.mail-archive.com/debian-bugs-rc@lists.debian.org/msg28251.html Source: OSVDB Type: UNKNOWN 20015 Source: CCN Type: OSVDB ID: 19717 AbiWord RTF Document Importer Overflow Source: CCN Type: OSVDB ID: 20015 AbiWord RTF Importer ie_imp_RTF.cpp Multiple Overflows Source: CCN Type: BID-14971 AbiWord RTF File Processing Buffer Overflow Vulnerability Source: BID Type: UNKNOWN 15096 Source: CCN Type: BID-15096 AbiWord Stack-Based Buffer Overflow Vulnerabilities Source: CCN Type: USN-188-1 AbiWord vulnerability Source: CCN Type: USN-203-1 Abiword vulnerabilities Source: VUPEN Type: Vendor Advisory ADV-2005-2086 Source: XF Type: UNKNOWN abiword-rtf-importer-bo(22454) Source: UBUNTU Type: UNKNOWN USN-203-1 Source: SUSE Type: SUSE-SR:2005:023 SUSE Security Summary Report | ||||||||
Vulnerable Configuration: | Configuration 1: Denotes that component is vulnerable | ||||||||
Oval Definitions | |||||||||
| |||||||||
BACK |