PT-2004-3662 · Wvware · Wv Library

Publicado

1970-01-01

·

Atualizado

2017-07-11

·

CVE-2004-0645

CVSS v2.0

10

Alta

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions wv library (wvWare) versions 0.7.4 through 0.7.6 wv library (wvWare) version 1.0.0
Description The issue involves multiple vulnerabilities in the wv library, which can lead to disruption of confidentiality, integrity, and availability of protected information. These vulnerabilities can be exploited remotely. A specific buffer overflow vulnerability exists in the wvHandleDateTimePicture function, allowing remote attackers to execute arbitrary code via a document with a long DateTime field.
Recommendations For wv library (wvWare) versions 0.7.4 through 0.7.6, consider disabling the wvHandleDateTimePicture function until a patch is available. For wv library (wvWare) version 1.0.0, consider disabling the wvHandleDateTimePicture function until a patch is available. As a temporary workaround, restrict access to documents with long DateTime fields to minimize the risk of exploitation.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

BDU:2015-01174
BDU:2015-02949
CVE-2004-0645
DSA-550-1
DSA-579-1

Produtos afetados

Wv Library