CVE-2012-3455

high
Published 2012-08-20 · Modified 2026-04-29
CVSS v3
CVSS v2
7.5
VIR risk
7.5

Description

Heap-based buffer overflow in the read function in filters/words/msword-odf/wv2/src/styles.cpp in the Microsoft import filter in KOffice 2.3.3 and earlier allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted ODF style in an ODF document. NOTE: this is the same vulnerability as CVE-2012-3456, but it was SPLIT by the CNA even though Calligra and KOffice share the same codebase.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — http://secunia.com/advisories/50199

Application impact

VendorProductVersionsFixed
kdekoffice{"endIncluding":"2.3.3"}
kdekoffice1.2
kdekoffice1.2.1
kdekoffice1.3
kdekoffice1.3.1
kdekoffice1.3.2
kdekoffice1.3.3
kdekoffice1.3.4
kdekoffice1.3.5
kdekoffice1.4
kdekoffice1.4.1
kdekoffice1.4.2
kdekoffice1.6.1

References

CWEs

CWE-119

Verify integrity in audit chain (admin only). AS-IS.