PT-2006-7581 · Gnome+1 · Libgsf+1

Infamous41Md

·

Published

1970-01-01

·

Updated

2018-10-17

·

CVE-2006-4514

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions libgsf versions prior to 1.14.2 libgsf-1.10.1 libgsf-1.6.0
Description The issue is related to a heap-based buffer overflow in the ole info read metabat function in the Gnome Structured File library (libgsf), which allows context-dependent attackers to execute arbitrary code via a large num metabat value in an OLE document. This can lead to a violation of confidentiality, integrity, and availability of protected information. The exploitation of this issue can be done remotely.
Recommendations For libgsf versions prior to 1.14.2, update to version 1.14.2 or later to resolve the issue. For libgsf-1.10.1 and libgsf-1.6.0, update to a version that is not affected by this issue, as these specific versions are vulnerable. As a temporary workaround, consider restricting access to the ole info read metabat function until a patch is available.

Fix

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-04267
BDU:2015-04268
BDU:2015-04921
BDU:2015-04922
BDU:2015-04923
BDU:2015-04924
BDU:2015-07334
BDU:2015-07335
BDU:2015-07336
BDU:2015-07337
BDU:2015-09532
CVE-2006-4514
DSA-1221-1
RHSA-2007:0011
RHSA-2007_0011

Affected Products

Red Hat
Libgsf