Bugzilla – Bug 118546
VUL-0: CVE-2005-2971: koffice rtf import filter vulnerability
Last modified: 2021-11-03 15:40:01 UTC
From: Chris Evans <scarybeasts@gmail.com> Reply-To: Chris Evans <scarybeasts@gmail.com> To: vendor-sec@lst.de, security@kde.org Subject: [vendor-sec] Koffice RTF import vulnerability Errors-To: vendor-sec-admin@lst.de Date: Thu, 22 Sep 2005 17:39:16 +0100 Hi, Advisory appended below. Release date is "whenever it's fixed". Might be worth running the rest of the test suite referenced. Cheers Chris CESA-2005-005 - rev 1 KWord RTF import heap corruption ================================ Programs affected: KWord Severity: Possible arbitrary code execution. Discovered date: ForgottenVendor notified date: Sep 22nd 2005 Demo RTF: http://scary.beasts.org/misc/out27.rtf (Simple RTF fuzz test suite at http://scary.beasts.org/misc/badrtfs.tar.bz2) rpm -q koffice-kword koffice-kword-1.4.1-4.fc4 Resultant stack trace: (gdb) bt #0 0x06d0706c in _int_malloc () from /lib/libc.so.6 #1 0x06d08492 in malloc () from /lib/libc.so.6 #2 0x06aaef56 in operator new () from /usr/lib/libstdc++.so.6 #3 0x06aaf06d in operator new[] () from /usr/lib/libstdc++.so.6 #4 0x012d18b9 in QString::setLength () from /usr/lib/qt-3.3/lib/libqt-mt.so.3 #5 0x012d1a28 in QString::grow () from /usr/lib/qt-3.3/lib/libqt-mt.so.3 #6 0x012d8143 in QString::operator+= () from /usr/lib/qt-3.3/lib/libqt-mt.so.3 #7 0x007466f9 in RTFImport::convert () from /usr/lib/kde3/librtfimport.so CESA-2005-005 - rev 1 Chris Evans scarybeasts@gmail.com
dirk, you can handle this for KDE too.
I'll check the RTF parser in Kopete against this input too.
SWAMPID: 2380
out27.rtf is successfully rejected by Kopete's RTF parser as an unparseable message. Takes a while, but no crash.
thanks! are you aware of any other rtf parser somewhere in our SVN? Can't find anything else..
affected products: 10.0, 9.3, 9.2, 9.1, 9.0 SLES9, SLES8, SLES8-SLC on all architectures
ok, forget the last comment. affected products: 10.0, 9.3, 9.2, 9.1, 9.0 SLES8-SLC on all architectures
CAN-2005-2971
CESA-2005-005
updates submitted. ETA disclosure date 10/10/2005
patchinfos are missing too (mls complained ;)
I forgot the patchinfos ... sorry. submitted now.
debian has just issued an advisory. SWAMP has CRD 7.11., who is correct now?
there was no coordinated release date as far as I know. KDE has published the advisory on October 11th.
auch gut... updates released.
CVE-2005-2971: CVSS v2 Base Score: 7.5 (AV:N/AC:L/Au:N/C:P/I:P/A:P)