CERT-In Vulnerability Note
CIVN-2006-0133
KOffice readBigBlockDepot PPT file handling integer overflow vulnerability
Original Issue Date:December 13, 2006
Severity Rating: HIGH
Systems Affected
KOffice version 1.6.0 and prior
Overview
A vulnerability has been reported in KOffice which could be exploited by remote attackers to execute arbitrary code or cause a denial of service attack.
Description
An integer overflow vulnerability has been reported in KPresenter import filter for Microsoft PowerPoint files in KOffice while handling a malformed powerpoint document. KLaola::readBigBlockDepot method in [ filters/olefilters/lib/klaola.cc] fails to validate user supplied data.
The vulnerability could be exploited by remote attackers to execute arbitrary code or cause denial of service attack by tricking a user to open a specially crafted powerpoint *.ppt file.
Solution
Upgrade to KOffice version 1.6.1
http://www.koffice.org/download/
Vendor Information
Koffice
http://www.koffice.org
References
FrSIRT
http://www.frsirt.com/english/advisories/2006/4771
Secunia
http://secunia.com/advisories/23143
Security Focus
http://www.securityfocus.com/bid/21354
Security Tracker
http://securitytracker.com/alerts/2006/Nov/1017318.html
CVE Name
CVE-2006-6120
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-2436857
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|