Heap-based buffer overflow in the read function in filters/words/msword-odf/wv2/src/styles.cpp in the Microsoft import filter in KOffice 2.3.3 and earlier allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted ODF style in an ODF document. NOTE: this is the same vulnerability as CVE-2012-3456, but it was SPLIT by the CNA even though Calligra and KOffice share the same codebase.
CVSS Details
- CVSS 3.1 Base Score: 7.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Freebsd | — | Upgrade koffice-kde4Upgrade kofficeUpgrade calligra | Dec 10, 2025 | Aug 26, 2012 |
| Suse | — | Upgrade koffice2-debuginfoUpgrade koffice2-kwordUpgrade koffice2-kpresenter-debuginfoUpgrade koffice2-kspread-debuginfoUpgrade koffice2-krita-debuginfoUpgrade koffice2-kplatoUpgrade koffice2-docUpgrade koffice2-kspreadUpgrade koffice2-kformulaUpgrade koffice2-kexiUpgrade koffice2-kword-debuginfoUpgrade koffice2-karbon-debuginfoUpgrade koffice2-kplato-debuginfoUpgrade koffice2Upgrade koffice2-kthesaurusUpgrade koffice2-develUpgrade koffice2-kexi-debuginfoUpgrade koffice2-kformula-debuginfoUpgrade koffice2-kthesaurus-debuginfoUpgrade koffice2-debugsourceUpgrade koffice2-karbonUpgrade koffice2-kpresenterUpgrade koffice2-krita | Dec 12, 2013 | Aug 20, 2012 |
| Ubuntu | — | Upgrade koffice | Nov 8, 2024 | Aug 20, 2012 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub