Back
CVE-2005-2972
Multiple stack-based buffer overflows in the RTF import feature in AbiWord before 2.2.11 allow user-assisted attackers to execute arbitrary code via an RTF file with long identifiers, which are not properly handled in the (1) ParseLevelText, (2) getCharsInsideBrace, (3) HandleLists, (4) or (5) HandleAbiLists functions in ie_imp_RTF.cpp, a different vulnerability than CVE-2005-2964.
Published: Oct 23, 2005
Modified: Jun 16, 2026
CWE-119
CVSS Metrics
Affected Products (1)
| Vendor | Product | Version |
|---|---|---|
| abisource | community_abiword | * |
GitHub Security Advisory GHSA-hw2f-4q5v-cv5j
Multiple stack-based buffer overflows in the RTF import feature in AbiWord before 2.2.11 allow...
References (28)
- http://scary.beasts.org/security/CESA-2005-006.txt Exploit, Vendor Advisory
- http://secunia.com/advisories/17199 Vendor Advisory
- http://secunia.com/advisories/17200 Vendor Advisory
- http://secunia.com/advisories/17213 Vendor Advisory
- http://secunia.com/advisories/17264 Vendor Advisory
- http://secunia.com/advisories/17551 Vendor Advisory
- http://www.abisource.com/changelogs/2.2.11.phtml
- http://www.debian.org/security/2005/dsa-894
- http://www.gentoo.org/security/en/glsa/glsa-200510-17.xml Patch, Vendor Advisory
- http://www.mail-archive.com/debian-bugs-rc%40lists.debian.org/msg28251.html
- http://www.osvdb.org/20015
- http://www.securityfocus.com/bid/15096
- http://www.vupen.com/english/advisories/2005/2086 Vendor Advisory
- https://usn.ubuntu.com/203-1/
- http://scary.beasts.org/security/CESA-2005-006.txt Exploit, Vendor Advisory
Risk Scores
CVSS Score
5.1 / 10
EPSS Score
4.10%
Top 10% most likely to be exploited
Threat Score
21.6 / 100
Data Sources
NVD
EPSS
GitHub