Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

David Tardon

#25471de 53,639
9.8CVSS total
Vulnerabilidades · 1
PT-2017-3255
9.8
2017-04-06
Document Liberation · Libmwaw · CVE-2017-9433
**Name of the Vulnerable Software and Affected Versions** Document Liberation Project libmwaw versions prior to 2017-04-08 **Description** The issue is caused by a heap-based buffer overflow related to the `MsWrd1Parser::readFootnoteCorrespondance` function in lib/MsWrd1Parser.cxx. This can be exploited by a remote attacker using a specially crafted document to execute arbitrary code. **Recommendations** For versions prior to 2017-04-08, update to a version released after 2017-04-08 to resolve the issue. As a temporary workaround, consider disabling the `MsWrd1Parser::readFootnoteCorrespondance` function until a patch is available.