PT-2007-1044 · Unknown · Abiword Link Grammar+2
Publicado
2007-11-08
·
Atualizado
2018-10-15
·
CVE-2007-5395
CVSS v2.0
10
Alta
| Vetor | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
Link Grammar versions 4.1b and possibly other versions
AbiWord Link Grammar version 4.2.4
liblink-grammar4 (affected versions not specified)
Description:
The issue is related to a stack-based buffer overflow in the
separate word function, which can be reached through the separate sentence function. This allows remote attackers to execute arbitrary code via a long word. Additionally, there are multiple vulnerabilities in the liblink-grammar4 package that can lead to breaches of confidentiality, integrity, and availability of protected information, and these can be exploited remotely.Recommendations:
For Link Grammar version 4.1b, consider disabling the
separate word function until a patch is available.
For AbiWord Link Grammar version 4.2.4, restrict access to the separate sentence function to minimize the risk of exploitation.
For liblink-grammar4, at the moment, there is no information about a newer version that contains a fix for this vulnerability.Buffer Overflow
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Abiword Link Grammar
Link Grammar
Liblink-Grammar4