PT-2006-7581 · Gnome+1 · Libgsf+1

Infamous41Md

·

Publicado

1970-01-01

·

Atualizado

2018-10-17

·

CVE-2006-4514

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions libgsf versions prior to 1.14.2 libgsf-1.10.1 libgsf-1.6.0
Description The issue is related to a heap-based buffer overflow in the ole info read metabat function in the Gnome Structured File library (libgsf), which allows context-dependent attackers to execute arbitrary code via a large num metabat value in an OLE document. This can lead to a violation of confidentiality, integrity, and availability of protected information. The exploitation of this issue can be done remotely.
Recommendations For libgsf versions prior to 1.14.2, update to version 1.14.2 or later to resolve the issue. For libgsf-1.10.1 and libgsf-1.6.0, update to a version that is not affected by this issue, as these specific versions are vulnerable. As a temporary workaround, consider restricting access to the ole info read metabat function until a patch is available.

Correção

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-04267
BDU:2015-04268
BDU:2015-04921
BDU:2015-04922
BDU:2015-04923
BDU:2015-04924
BDU:2015-07334
BDU:2015-07335
BDU:2015-07336
BDU:2015-07337
BDU:2015-09532
CVE-2006-4514
DSA-1221-1
RHSA-2007:0011
RHSA-2007_0011

Produtos afetados

Red Hat
Libgsf