wv2 Remote Buffer Overflow Vulnerability
BID:18437
Info
wv2 Remote Buffer Overflow Vulnerability
| Bugtraq ID: | 18437 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2006-2197 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 14 2006 12:00AM |
| Updated: | Mar 19 2015 09:17AM |
| Credit: | The vendor disclosed this issue. |
| Vulnerable: |
wvWare wv2 0.2.2 Ubuntu Ubuntu Linux 5.10 powerpc Ubuntu Ubuntu Linux 5.10 i386 Ubuntu Ubuntu Linux 5.10 amd64 Ubuntu Ubuntu Linux 5.0 4 powerpc Ubuntu Ubuntu Linux 5.0 4 i386 Ubuntu Ubuntu Linux 5.0 4 amd64 Ubuntu Ubuntu Linux 6.06 LTS powerpc Ubuntu Ubuntu Linux 6.06 LTS i386 Ubuntu Ubuntu Linux 6.06 LTS amd64 SuSE SUSE Linux Enterprise Server 9 SuSE SUSE Linux Enterprise Server 8 S.u.S.E. UnitedLinux 1.0 S.u.S.E. SuSE Linux Standard Server 8.0 S.u.S.E. SuSE Linux School Server for i386 S.u.S.E. SUSE LINUX Retail Solution 8.0 S.u.S.E. SuSE Linux Openexchange Server 4.0 S.u.S.E. SuSE Linux Open-Xchange 4.1 S.u.S.E. Open-Enterprise-Server 9.0 S.u.S.E. Open-Enterprise-Server 1 S.u.S.E. Office Server S.u.S.E. Novell Linux Desktop 9.0 S.u.S.E. Novell Linux Desktop 1.0 S.u.S.E. Linux Professional 10.0 OSS S.u.S.E. Linux Professional 10.0 S.u.S.E. Linux Professional 9.3 x86_64 S.u.S.E. Linux Professional 9.3 S.u.S.E. Linux Professional 9.2 x86_64 S.u.S.E. Linux Professional 9.2 S.u.S.E. Linux Professional 9.1 x86_64 S.u.S.E. Linux Professional 9.1 S.u.S.E. Linux Professional 10.1 S.u.S.E. Linux Personal 10.0 OSS S.u.S.E. Linux Personal 9.3 x86_64 S.u.S.E. Linux Personal 9.3 S.u.S.E. Linux Personal 9.2 x86_64 S.u.S.E. Linux Personal 9.2 S.u.S.E. Linux Personal 9.1 x86_64 S.u.S.E. Linux Personal 9.1 S.u.S.E. Linux Personal 10.1 S.u.S.E. Linux Openexchange Server S.u.S.E. Linux Office Server S.u.S.E. Linux Enterprise Server for S/390 9.0 S.u.S.E. Linux Enterprise Server for S/390 S.u.S.E. Linux Desktop 1.0 S.u.S.E. Linux Database Server 0 S.u.S.E. Linux Connectivity Server Mandriva Linux Mandrake 2006.0 x86_64 Mandriva Linux Mandrake 2006.0 MandrakeSoft Corporate Server 3.0 x86_64 MandrakeSoft Corporate Server 3.0 Gentoo Linux Debian Linux 3.1 sparc Debian Linux 3.1 s/390 Debian Linux 3.1 ppc Debian Linux 3.1 mipsel Debian Linux 3.1 mips Debian Linux 3.1 m68k Debian Linux 3.1 ia-64 Debian Linux 3.1 ia-32 Debian Linux 3.1 hppa Debian Linux 3.1 arm Debian Linux 3.1 amd64 Debian Linux 3.1 alpha Debian Linux 3.1 |
| Not Vulnerable: |
wvWare wv2 0.2.3 |
Discussion
wv2 Remote Buffer Overflow Vulnerability
The wv2 library is prone to a remote buffer-overflow vulnerability. This issue is due to the library's failure to properly bounds-check user-supplied input before copying it to an insufficiently sized memory buffer.
This issue allows remote attackers to execute arbitrary machine code in the context of applications that use the affected library to parse malicious Microsoft Word files.
Version 0.2.2 of the wv2 library is vulnerable to this issue; other versions may also be affected.
The wv2 library is prone to a remote buffer-overflow vulnerability. This issue is due to the library's failure to properly bounds-check user-supplied input before copying it to an insufficiently sized memory buffer.
This issue allows remote attackers to execute arbitrary machine code in the context of applications that use the affected library to parse malicious Microsoft Word files.
Version 0.2.2 of the wv2 library is vulnerable to this issue; other versions may also be affected.
Exploit / POC
wv2 Remote Buffer Overflow Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected]
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected]
Solution / Fix
wv2 Remote Buffer Overflow Vulnerability
Solution:
The vendor has released a fixed version of the affected library.
Please see the referenced advisories for more information on obtaining and applying fixes.
wvWare wv2 0.2.2
Solution:
The vendor has released a fixed version of the affected library.
Please see the referenced advisories for more information on obtaining and applying fixes.
wvWare wv2 0.2.2
-
Debian libwv2-1_0.2.2-1sarge1_alpha.deb
http://security.debian.org/pool/updates/main/w/wv2/libwv2-1_0.2.2-1sar ge1_alpha.deb -
Debian libwv2-1_0.2.2-1sarge1_alpha.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/w/wv2/libwv2-1_0.2.2-1sar ge1_alpha.deb -
Debian libwv2-1_0.2.2-1sarge1_amd64.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/w/wv2/libwv2-1_0.2.2-1sar ge1_amd64.deb -
Debian libwv2-1_0.2.2-1sarge1_arm.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/w/wv2/libwv2-1_0.2.2-1sar ge1_arm.deb -
Debian libwv2-1_0.2.2-1sarge1_hppa.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/w/wv2/libwv2-1_0.2.2-1sar ge1_hppa.deb -
Debian libwv2-1_0.2.2-1sarge1_i386.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/w/wv2/libwv2-1_0.2.2-1sar ge1_i386.deb -
Debian libwv2-1_0.2.2-1sarge1_ia64.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/w/wv2/libwv2-1_0.2.2-1sar ge1_ia64.deb -
Debian libwv2-1_0.2.2-1sarge1_m68k.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/w/wv2/libwv2-1_0.2.2-1sar ge1_m68k.deb -
Debian libwv2-1_0.2.2-1sarge1_mips.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/w/wv2/libwv2-1_0.2.2-1sar ge1_mips.deb -
Debian libwv2-1_0.2.2-1sarge1_mipsel.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/w/wv2/libwv2-1_0.2.2-1sar ge1_mipsel.deb -
Debian libwv2-1_0.2.2-1sarge1_powerpc.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/w/wv2/libwv2-1_0.2.2-1sar ge1_powerpc.deb -
Debian libwv2-1_0.2.2-1sarge1_s390.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/w/wv2/libwv2-1_0.2.2-1sar ge1_s390.deb -
Debian libwv2-1_0.2.2-1sarge1_sparc.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/w/wv2/libwv2-1_0.2.2-1sar ge1_sparc.deb -
Debian libwv2-dev_0.2.2-1sarge1_alpha.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/w/wv2/libwv2-dev_0.2.2-1s arge1_alpha.deb -
Debian libwv2-dev_0.2.2-1sarge1_amd64.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/w/wv2/libwv2-dev_0.2.2-1s arge1_amd64.deb -
Debian libwv2-dev_0.2.2-1sarge1_arm.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/w/wv2/libwv2-dev_0.2.2-1s arge1_arm.deb -
Debian libwv2-dev_0.2.2-1sarge1_hppa.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/w/wv2/libwv2-dev_0.2.2-1s arge1_hppa.deb -
Debian libwv2-dev_0.2.2-1sarge1_ia64.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/w/wv2/libwv2-dev_0.2.2-1s arge1_ia64.deb -
Debian libwv2-dev_0.2.2-1sarge1_m68k.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/w/wv2/libwv2-dev_0.2.2-1s arge1_m68k.deb -
Debian libwv2-dev_0.2.2-1sarge1_mips.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/w/wv2/libwv2-dev_0.2.2-1s arge1_mips.deb -
Debian libwv2-dev_0.2.2-1sarge1_mipsel.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/w/wv2/libwv2-dev_0.2.2-1s arge1_mipsel.deb -
Debian libwv2-dev_0.2.2-1sarge1_powerpc.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/w/wv2/libwv2-dev_0.2.2-1s arge1_powerpc.deb -
Debian libwv2-dev_0.2.2-1sarge1_s390.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/w/wv2/libwv2-dev_0.2.2-1s arge1_s390.deb -
Debian libwv2-dev_0.2.2-1sarge1_sparc.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/w/wv2/libwv2-dev_0.2.2-1s arge1_sparc.deb -
Mandriva lib64wv2_1-0.2.2-3.1.20060mdk.x86_64.rpm
Mandriva Linux 2006.0/X86_64:
http://wwwnew.mandriva.com/en/downloads/ -
Mandriva libwv2_1-0.2.2-3.1.20060mdk.i586.rpm
Mandriva Linux 2006.0:
http://wwwnew.mandriva.com/en/downloads/ -
Ubuntu libwv2-1_0.2.2-1ubuntu1.1_amd64.deb
Ubuntu 5.04:
http://security.ubuntu.com/ubuntu/pool/universe/w/wv2/libwv2-1_0.2.2-1 ubuntu1.1_amd64.deb -
Ubuntu libwv2-1_0.2.2-1ubuntu1.1_i386.deb
Ubuntu 5.04:
http://security.ubuntu.com/ubuntu/pool/universe/w/wv2/libwv2-1_0.2.2-1 ubuntu1.1_i386.deb -
Ubuntu libwv2-1_0.2.2-1ubuntu1.1_powerpc.deb
Ubuntu 5.04:
http://security.ubuntu.com/ubuntu/pool/universe/w/wv2/libwv2-1_0.2.2-1 ubuntu1.1_powerpc.deb -
Ubuntu libwv2-1c2_0.2.2-1ubuntu2.1_amd64.deb
Ubuntu 5.10:
http://security.ubuntu.com/ubuntu/pool/main/w/wv2/libwv2-1c2_0.2.2-1ub untu2.1_amd64.deb -
Ubuntu libwv2-1c2_0.2.2-1ubuntu2.1_i386.deb
Ubuntu 5.10:
http://security.ubuntu.com/ubuntu/pool/main/w/wv2/libwv2-1c2_0.2.2-1ub untu2.1_i386.deb -
Ubuntu libwv2-1c2_0.2.2-1ubuntu2.1_powerpc.deb
Ubuntu 5.10:
http://security.ubuntu.com/ubuntu/pool/main/w/wv2/libwv2-1c2_0.2.2-1ub untu2.1_powerpc.deb -
Ubuntu libwv2-1c2_0.2.2-5ubuntu0.1_amd64.deb
Ubuntu 6.06 LTS:
http://security.ubuntu.com/ubuntu/pool/main/w/wv2/libwv2-1c2_0.2.2-5ub untu0.1_amd64.deb -
Ubuntu libwv2-1c2_0.2.2-5ubuntu0.1_i386.deb
Ubuntu 6.06 LTS:
http://security.ubuntu.com/ubuntu/pool/main/w/wv2/libwv2-1c2_0.2.2-5ub untu0.1_i386.deb -
Ubuntu libwv2-1c2_0.2.2-5ubuntu0.1_powerpc.deb
Ubuntu 6.06 LTS:
http://security.ubuntu.com/ubuntu/pool/main/w/wv2/libwv2-1c2_0.2.2-5ub untu0.1_powerpc.deb -
Ubuntu libwv2-dev_0.2.2-1ubuntu1.1_amd64.deb
Ubuntu 5.04:
http://security.ubuntu.com/ubuntu/pool/universe/w/wv2/libwv2-dev_0.2.2 -1ubuntu1.1_amd64.deb -
Ubuntu libwv2-dev_0.2.2-1ubuntu1.1_i386.deb
Ubuntu 5.04:
http://security.ubuntu.com/ubuntu/pool/universe/w/wv2/libwv2-dev_0.2.2 -1ubuntu1.1_i386.deb -
Ubuntu libwv2-dev_0.2.2-1ubuntu1.1_powerpc.deb
Ubuntu 5.04:
http://security.ubuntu.com/ubuntu/pool/universe/w/wv2/libwv2-dev_0.2.2 -1ubuntu1.1_powerpc.deb -
Ubuntu libwv2-dev_0.2.2-1ubuntu2.1_amd64.deb
Ubuntu 5.10:
http://security.ubuntu.com/ubuntu/pool/main/w/wv2/libwv2-dev_0.2.2-1ub untu2.1_amd64.deb -
Ubuntu libwv2-dev_0.2.2-1ubuntu2.1_i386.deb
Ubuntu 5.10:
http://security.ubuntu.com/ubuntu/pool/main/w/wv2/libwv2-dev_0.2.2-1ub untu2.1_i386.deb -
Ubuntu libwv2-dev_0.2.2-1ubuntu2.1_powerpc.deb
Ubuntu 5.10:
http://security.ubuntu.com/ubuntu/pool/main/w/wv2/libwv2-dev_0.2.2-1ub untu2.1_powerpc.deb -
Ubuntu libwv2-dev_0.2.2-5ubuntu0.1_amd64.deb
Ubuntu 6.06 LTS:
http://security.ubuntu.com/ubuntu/pool/main/w/wv2/libwv2-dev_0.2.2-5ub untu0.1_amd64.deb -
Ubuntu libwv2-dev_0.2.2-5ubuntu0.1_i386.deb
Ubuntu 6.06 LTS:
http://security.ubuntu.com/ubuntu/pool/main/w/wv2/libwv2-dev_0.2.2-5ub untu0.1_i386.deb -
Ubuntu libwv2-dev_0.2.2-5ubuntu0.1_powerpc.deb
Ubuntu 6.06 LTS:
http://security.ubuntu.com/ubuntu/pool/main/w/wv2/libwv2-dev_0.2.2-5ub untu0.1_powerpc.deb -
wvWare wv2-0.2.3.tar.bz2
http://prdownloads.sourceforge.net/wvware/wv2-0.2.3.tar.bz2?download
References
wv2 Remote Buffer Overflow Vulnerability
References:
References:
- Release Name: 0.2.3 (wvWare)
- wvWare Homepage (wvWare)