« Volver al listado

CVE-2012-3455

Estado: ModificadaAlta (7.5)—

Heap-based buffer overflow in the read function in filters/words/msword-odf/wv2/src/styles.cpp in the Microsoft import filter in KOffice 2.3.3 and earlier allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted ODF style in an ODF document. NOTE: this is the same vulnerability as CVE-2012-3456, but it was SPLIT by the CNA even though Calligra and KOffice share the same codebase.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2012-3455",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 7.5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "secalert@redhat.com",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2012-08-20T19:55:05.433",
  "references": [
    {
      "url": "http://lists.opensuse.org/opensuse-updates/2012-08/msg00040.html",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://media.blackhat.com/bh-us-12/Briefings/C_Miller/BH_US_12_Miller_NFC_attack_surface_WP.pdf",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://secunia.com/advisories/50199",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://www.kde.org/info/security/advisory-20120810-1.txt",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://www.openwall.com/lists/oss-security/2012/08/04/1",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://www.openwall.com/lists/oss-security/2012/08/04/5",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://www.openwall.com/lists/oss-security/2012/08/06/1",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://www.openwall.com/lists/oss-security/2012/08/06/6",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://www.openwall.com/lists/oss-security/2012/08/10/1",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://www.securityfocus.com/bid/54816",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://www.ubuntu.com/usn/USN-1526-1",
      "source": "secalert@redhat.com"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/77483",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://lists.opensuse.org/opensuse-updates/2012-08/msg00040.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://media.blackhat.com/bh-us-12/Briefings/C_Miller/BH_US_12_Miller_NFC_attack_surface_WP.pdf",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/50199",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.kde.org/info/security/advisory-20120810-1.txt",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.openwall.com/lists/oss-security/2012/08/04/1",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.openwall.com/lists/oss-security/2012/08/04/5",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.openwall.com/lists/oss-security/2012/08/06/1",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.openwall.com/lists/oss-security/2012/08/06/6",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.openwall.com/lists/oss-security/2012/08/10/1",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/54816",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.ubuntu.com/usn/USN-1526-1",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/77483",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-119"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Heap-based buffer overflow in the read function in filters/words/msword-odf/wv2/src/styles.cpp in the Microsoft import filter in KOffice 2.3.3 and earlier allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted ODF style in an ODF document.  NOTE: this is the same vulnerability as CVE-2012-3456, but it was SPLIT by the CNA even though Calligra and KOffice share the same codebase."
    },
    {
      "lang": "es",
      "value": "Desbordamiento de búfer de memoria dinámica en la función de lectura en filters/words/msword-odf/wv2/src/styles.cpp en el filtro Microsoft import filter in KOffice 2.3.3 y anteriores que permite a atacantes remotos causar una denegación de servicio (caída de la aplicación) y posiblemente la ejecución de código arbitrario a través de un estilo ODF manipulado en un documento ODF. NOTA:esta es la misma vulnerabilidad que CVE-2012-3456, pero fue dividida por el CNA debido a que Calligra y KOffice comparten parte del mismo código."
    }
  ],
  "lastModified": "2026-06-16T23:43:15.363",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:kde:koffice:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "23BD6648-1429-46D3-8832-EAF6078F3A89",
              "versionEndIncluding": "2.3.3"
            },
            {
              "criteria": "cpe:2.3:a:kde:koffice:1.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "ADDFDF11-A965-48B0-AC5A-1AB34A8FE93B"
            },
            {
              "criteria": "cpe:2.3:a:kde:koffice:1.2.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C88CD4B3-FC36-4009-AF40-E5930167B62A"
            },
            {
              "criteria": "cpe:2.3:a:kde:koffice:1.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "053435DD-BFDF-4C39-9919-11C42D569085"
            },
            {
              "criteria": "cpe:2.3:a:kde:koffice:1.3:beta1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "022B3A2E-BB9E-4A57-8E34-32BCA5A72CA0"
            },
            {
              "criteria": "cpe:2.3:a:kde:koffice:1.3:beta2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4961F911-B185-440D-9977-FDA238BB1EC4"
            },
            {
              "criteria": "cpe:2.3:a:kde:koffice:1.3:beta3:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A15C155C-4CDB-43CD-86F3-F969B6CBADF9"
            },
            {
              "criteria": "cpe:2.3:a:kde:koffice:1.3.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E9BB1A3C-3348-4545-A513-E504B33F72AB"
            },
            {
              "criteria": "cpe:2.3:a:kde:koffice:1.3.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "CD45E2C8-0B0E-484F-8050-94BF77798183"
            },
            {
              "criteria": "cpe:2.3:a:kde:koffice:1.3.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4EAA654E-9DD4-4614-92D7-EF4D676B3A18"
            },
            {
              "criteria": "cpe:2.3:a:kde:koffice:1.3.4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "99E505C5-C809-425F-AF68-A8D79330DE83"
            },
            {
              "criteria": "cpe:2.3:a:kde:koffice:1.3.5:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "267A2353-C2B9-4D7F-9290-9E3AC1B8C8D5"
            },
            {
              "criteria": "cpe:2.3:a:kde:koffice:1.4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "37C08E0A-651F-458B-BCEC-A30DCD527E47"
            },
            {
              "criteria": "cpe:2.3:a:kde:koffice:1.4.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6000D6AF-C056-4BC0-A54C-72E23E52AB92"
            },
            {
              "criteria": "cpe:2.3:a:kde:koffice:1.4.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A7D036E4-FA49-417D-968B-9D73B16A09BA"
            },
            {
              "criteria": "cpe:2.3:a:kde:koffice:1.6.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C69061C5-F7AF-4F1B-B6B1-3F76CF61F8AE"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "secalert@redhat.com"
}