Antiword: User-assisted execution of arbitrary code A buffer overflow vulnerability in Antiword could result in execution of arbitrary code or Denial of Service. antiword 2015-02-07 2015-02-07 531404 remote 0.37-r1 0.37-r1

Antiword is a free MS Word reader.

A buffer overflow vulnerability has been found in wordole.c in Antiword.

A remote attacker could entice a user to open a specially crafted document using Antiword, possibly resulting in execution of arbitrary code with the privileges of the process or a Denial of Service condition.

There is no known workaround at this time.

All Antiword users should upgrade to the latest version:

# emerge --sync # emerge --ask --oneshot --verbose ">=app-text/antiword-0.37-r1"
CVE-2014-8123 ackle ackle