|
Bugzilla – Full Text Bug Listing |
| Summary: | VUL-0: CVE-2005-2971: koffice rtf import filter vulnerability | ||
|---|---|---|---|
| Product: | [Novell Products] SUSE Security Incidents | Reporter: | Marcus Meissner <meissner> |
| Component: | Incidents | Assignee: | Security Team bot <security-team> |
| Status: | RESOLVED FIXED | QA Contact: | Security Team bot <security-team> |
| Severity: | Normal | ||
| Priority: | P5 - None | CC: | dmueller, mls, security-team, wstephenson |
| Version: | unspecified | ||
| Target Milestone: | --- | ||
| Hardware: | Other | ||
| OS: | All | ||
| Whiteboard: | CVE-2005-2971: CVSS v2 Base Score: 7.5 (AV:N/AC:L/Au:N/C:P/I:P/A:P) | ||
| Found By: | Other | Services Priority: | |
| Business Priority: | Blocker: | --- | |
| Marketing QA Status: | --- | IT Deployment: | --- |
|
Description
Marcus Meissner
2005-09-23 07:50:19 UTC
dirk, you can handle this for KDE too. I'll check the RTF parser in Kopete against this input too. SWAMPID: 2380 out27.rtf is successfully rejected by Kopete's RTF parser as an unparseable message. Takes a while, but no crash. thanks! are you aware of any other rtf parser somewhere in our SVN? Can't find anything else.. affected products: 10.0, 9.3, 9.2, 9.1, 9.0 SLES9, SLES8, SLES8-SLC on all architectures ok, forget the last comment. affected products: 10.0, 9.3, 9.2, 9.1, 9.0 SLES8-SLC on all architectures CAN-2005-2971 CESA-2005-005 updates submitted. ETA disclosure date 10/10/2005 patchinfos are missing too (mls complained ;) CAN-2005-2971 I forgot the patchinfos ... sorry. submitted now. debian has just issued an advisory. SWAMP has CRD 7.11., who is correct now? there was no coordinated release date as far as I know. KDE has published the advisory on October 11th. auch gut... updates released. CVE-2005-2971: CVSS v2 Base Score: 7.5 (AV:N/AC:L/Au:N/C:P/I:P/A:P) |