PT-2004-3662 · Wvware · Wv Library

Published

1970-01-01

·

Updated

2017-07-11

·

CVE-2004-0645

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions wv library (wvWare) versions 0.7.4 through 0.7.6 wv library (wvWare) version 1.0.0
Description The issue involves multiple vulnerabilities in the wv library, which can lead to disruption of confidentiality, integrity, and availability of protected information. These vulnerabilities can be exploited remotely. A specific buffer overflow vulnerability exists in the wvHandleDateTimePicture function, allowing remote attackers to execute arbitrary code via a document with a long DateTime field.
Recommendations For wv library (wvWare) versions 0.7.4 through 0.7.6, consider disabling the wvHandleDateTimePicture function until a patch is available. For wv library (wvWare) version 1.0.0, consider disabling the wvHandleDateTimePicture function until a patch is available. As a temporary workaround, restrict access to documents with long DateTime fields to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

BDU:2015-01174
BDU:2015-02949
CVE-2004-0645
DSA-550-1
DSA-579-1

Affected Products

Wv Library