CVE-2005-2972

Multiple stack-based buffer overflows in the RTF import feature in AbiWord before 2.2.11 allow user-assisted attackers to execute arbitrary code via an RTF file with long identifiers, which are not properly handled in the (1) ParseLevelText, (2) getCharsInsideBrace, (3) HandleLists, (4) or (5) HandleAbiLists functions in ie_imp_RTF.cpp, a different vulnerability than CVE-2005-2964.
Configurations

Configuration 1 (hide)

cpe:2.3:a:abisource:community_abiword:*:*:*:*:*:*:*:*

History

07 Nov 2023, 01:57

Type Values Removed Values Added
References
  • {'url': 'http://www.mail-archive.com/debian-bugs-rc@lists.debian.org/msg28251.html', 'name': 'http://www.mail-archive.com/debian-bugs-rc@lists.debian.org/msg28251.html', 'tags': ['Vendor Advisory'], 'refsource': 'MISC'}
  • () http://www.mail-archive.com/debian-bugs-rc%40lists.debian.org/msg28251.html -

Information

Published : 2005-10-23 10:02

Updated : 2024-02-28 10:42


NVD link : CVE-2005-2972

Mitre link : CVE-2005-2972

CVE.ORG link : CVE-2005-2972


JSON object : View

Products Affected

abisource

  • community_abiword
CWE
CWE-119

Improper Restriction of Operations within the Bounds of a Memory Buffer