CVE-2012-3456

high
Published 2012-08-20 · Modified 2026-04-29
CVSS v3
CVSS v2
7.5
VIR risk
7.5

Description

Heap-based buffer overflow in the read function in filters/words/msword-odf/wv2/src/styles.cpp in the Microsoft import filter in Calligra 2.4.3 and earlier allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted ODF style in an ODF document. NOTE: this is the same vulnerability as CVE-2012-3455, but it was SPLIT by the CNA even though Calligra and KOffice share the same codebase.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2012-3456

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — http://secunia.com/advisories/50050

OS impact

OSVersionStatusFixed in
debian debianbookwormfixed1:2.4.3-2
debian debianbullseyefixed1:2.4.3-2
debian debianforkyfixed1:2.4.3-2
debian debiansidfixed1:2.4.3-2
debian debiantrixiefixed1:2.4.3-2

Application impact

VendorProductVersionsFixed
calligracalligra{"endIncluding":"2.4.3"}
calligracalligra2.4
calligracalligra2.4.1
calligracalligra2.4.2

References

CWEs

CWE-119

Verify integrity in audit chain (admin only). AS-IS.