Heap-based buffer overflow in the read function in filters/words/msword-odf/wv2/src/styles.cpp in the Microsoft import filter in Calligra 2.4.3 and earlier allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted ODF style in an ODF document. NOTE: this is the same vulnerability as CVE-2012-3455, but it was SPLIT by the CNA even though Calligra and KOffice share the same codebase.
CVSS Details
- CVSS 3.1 Base Score: 8.4
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade calligra | Jul 30, 2024 | Aug 20, 2012 |
| Freebsd | — | Upgrade koffice-kde4Upgrade kofficeUpgrade calligra | Dec 10, 2025 | Aug 26, 2012 |
| Gentoo Linux | — | Upgrade app-office/calligra. | Oct 30, 2017 | Aug 20, 2012 |
| Suse | — | Upgrade calligra-braindumpUpgrade calligraUpgrade calligra-kexi-xbase-driverUpgrade calligra-docUpgrade calligra-kexiUpgrade calligra-kthesaurusUpgrade calligra-kexi-mysql-driverUpgrade calligra-kexi-spreadsheet-importUpgrade calligra-karbonUpgrade calligra-sheetsUpgrade calligra-wordsUpgrade calligra-develUpgrade calligra-toolsUpgrade calligra-flowUpgrade calligra-kexi-postgresql-driverUpgrade calligra-kritaUpgrade calligra-kexi-mssql-driverUpgrade calligra-stageUpgrade calligra-plan | Feb 17, 2015 | Aug 20, 2012 |
| Ubuntu | — | Upgrade calligra | Nov 8, 2024 | Aug 20, 2012 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub