CVE-2005-2971: Buffer Overflow
Published Oct 20, 2005
·Updated
Heap-based buffer overflow in the KWord RTF importer for KOffice 1.2.0 through 1.4.1 allows remote attackers to execute arbitrary code via a crafted RTF file.
Affected Software
13 affected components
KDE Koffice=1.3_beta2
KDE Koffice=1.3.4
KDE Koffice=1.4.1
KDE Koffice=1.3.3
KDE Koffice=1.3.5
KDE Koffice=1.3_beta3
KDE Koffice=1.3
KDE Koffice=1.2.1
KDE Koffice=1.3_beta1
KDE Koffice=1.3.1
KDE Koffice=1.2
KDE Koffice=1.4
KDE Koffice=1.3.2
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Oct 20, 2005
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-2971?
CVE-2005-2971 has a high severity rating due to its potential to allow remote code execution through crafted RTF files.
2
How do I fix CVE-2005-2971?
To fix CVE-2005-2971, update KOffice to the latest version that addresses this vulnerability.
3
What versions of KOffice are affected by CVE-2005-2971?
KOffice versions from 1.2.0 to 1.4.1, including earlier beta versions, are affected by CVE-2005-2971.
4
What kind of attack does CVE-2005-2971 enable?
CVE-2005-2971 enables remote attackers to execute arbitrary code on the affected systems.
5
Is there a workaround for CVE-2005-2971 if I cannot update KOffice?
There is no official workaround for CVE-2005-2971; updating KOffice is the recommended solution.