wv2 整数溢出漏洞

漏洞信息详情

wv2 整数溢出漏洞

漏洞简介

wv2 存在整数溢出,攻击者可能通过特制的Microsoft Word 文档上下文依赖来执行任意代码。

漏洞公告

目前厂商已经发布了相关补丁,请到厂商的主页下载:

wvWare wv2 0.2.2

Debian libwv2-1_0.2.2-1sarge1_alpha.deb

http://security.debian.org/pool/updates/main/w/wv2/libwv2-1_0.2.2-1sar ge1_alpha.deb

Debian libwv2-1_0.2.2-1sarge1_alpha.deb

Debian GNU/Linux 3.1 alias sarge

http://security.debian.org/pool/updates/main/w/wv2/libwv2-1_0.2.2-1sar ge1_alpha.deb

Debian libwv2-1_0.2.2-1sarge1_amd64.deb

Debian GNU/Linux 3.1 alias sarge

http://security.debian.org/pool/updates/main/w/wv2/libwv2-1_0.2.2-1sar ge1_amd64.deb

Debian libwv2-1_0.2.2-1sarge1_arm.deb

Debian GNU/Linux 3.1 alias sarge

http://security.debian.org/pool/updates/main/w/wv2/libwv2-1_0.2.2-1sar ge1_arm.deb

Debian libwv2-1_0.2.2-1sarge1_hppa.deb

Debian GNU/Linux 3.1 alias sarge

http://security.debian.org/pool/updates/main/w/wv2/libwv2-1_0.2.2-1sar ge1_hppa.deb

Debian libwv2-1_0.2.2-1sarge1_i386.deb

Debian GNU/Linux 3.1 alias sarge

http://security.debian.org/pool/updates/main/w/wv2/libwv2-1_0.2.2-1sar ge1_i386.deb

Debian libwv2-1_0.2.2-1sarge1_ia64.deb

Debian GNU/Linux 3.1 alias sarge

http://security.debian.org/pool/updates/main/w/wv2/libwv2-1_0.2.2-1sar ge1_ia64.deb

Debian libwv2-1_0.2.2-1sarge1_m68k.deb

Debian GNU/Linux 3.1 alias sarge

http://security.debian.org/pool/updates/main/w/wv2/libwv2-1_0.2.2-1sar ge1_m68k.deb

Debian libwv2-1_0.2.2-1sarge1_mips.deb

Debian GNU/Linux 3.1 alias sarge

http://security.debian.org/pool/updates/main/w/wv2/libwv2-1_0.2.2-1sar ge1_mips.deb

Debian libwv2-1_0.2.2-1sarge1_mipsel.deb

Debian GNU/Linux 3.1 alias sarge

http://security.debian.org/pool/updates/main/w/wv2/libwv2-1_0.2.2-1sar ge1_mipsel.deb

Debian libwv2-1_0.2.2-1sarge1_powerpc.deb

Debian GNU/Linux 3.1 alias sarge

http://security.debian.org/pool/updates/main/w/wv2/libwv2-1_0.2.2-1sar ge1_powerpc.deb

Debian libwv2-1_0.2.2-1sarge1_s390.deb

Debian GNU/Linux 3.1 alias sarge

http://security.debian.org/pool/updates/main/w/wv2/libwv2-1_0.2.2-1sar ge1_s390.deb

Debian libwv2-1_0.2.2-1sarge1_sparc.deb

Debian GNU/Linux 3.1 alias sarge

http://security.debian.org/pool/updates/main/w/wv2/libwv2-1_0.2.2-1sar ge1_sparc.deb

Debian libwv2-dev_0.2.2-1sarge1_alpha.deb

Debian GNU/Linux 3.1 alias sarge

http://security.debian.org/pool/updates/main/w/wv2/libwv2-dev_0.2.2-1s arge1_alpha.deb

Debian libwv2-dev_0.2.2-1sarge1_amd64.deb

Debian GNU/Linux 3.1 alias sarge

http://security.debian.org/pool/updates/main/w/wv2/libwv2-dev_0.2.2-1s arge1_amd64.deb

Debian libwv2-dev_0.2.2-1sarge1_arm.deb

Debian GNU/Linux 3.1 alias sarge

http://security.debian.org/pool/updates/main/w/wv2/libwv2-dev_0.2.2-1s arge1_arm.deb

Debian libwv2-dev_0.2.2-1sarge1_hppa.deb

Debian GNU/Linux 3.1 alias sarge

http://security.debian.org/pool/updates/main/w/wv2/libwv2-dev_0.2.2-1s arge1_hppa.deb

Debian libwv2-dev_0.2.2-1sarge1_ia64.deb

Debian GNU/Linux 3.1 alias sarge

http://security.debian.org/pool/updates/main/w/wv2/libwv2-dev_0.2.2-1s arge1_ia64.deb

Debian libwv2-dev_0.2.2-1sarge1_m68k.deb

Debian GNU/Linux 3.1 alias sarge

http://security.debian.org/pool/updates/main/w/wv2/libwv2-dev_0.2.2-1s arge1_m68k.deb

Debian libwv2-dev_0.2.2-1sarge1_mips.deb

Debian GNU/Linux 3.1 alias sarge

http://security.debian.org/pool/updates/main/w/wv2/libwv2-dev_0.2.2-1s arge1_mips.deb

Debian libwv2-dev_0.2.2-1sarge1_mipsel.deb

Debian GNU/Linux 3.1 alias sarge

http://security.debian.org/pool/updates/main/w/wv2/libwv2-dev_0.2.2-1s arge1_mipsel.deb

Debian libwv2-dev_0.2.2-1sarge1_powerpc.deb

Debian GNU/Linux 3.1 alias sarge

http://security.debian.org/pool/updates/main/w/wv2/libwv2-dev_0.2.2-1s arge1_powerpc.deb

Debian libwv2-dev_0.2.2-1sarge1_s390.deb

Debian GNU/Linux 3.1 alias sarge

http://security.debian.org/pool/updates/main/w/wv2/libwv2-dev_0.2.2-1s arge1_s390.deb

Debian libwv2-dev_0.2.2-1sarge1_sparc.deb

Debian GNU/Linux 3.1 alias sarge

http://security.debian.org/pool/updates/main/w/wv2/libwv2-dev_0.2.2-1s arge1_sparc.deb

Mandriva lib64wv2_1-0.2.2-3.1.20060mdk.x86_64.rpm

Mandriva Linux 2006.0/X86_64:

http://wwwnew.mandriva.com/en/downloads/

Mandriva libwv2_1-0.2.2-3.1.20060mdk.i586.rpm

Mandriva Linux 2006.0:

h

参考网址

来源: BID

名称: 18437

链接:http://www.securityfocus.com/bid/18437

来源: GENTOO

名称: GLSA-200606-24

链接:http://www.gentoo.org/security/en/glsa/glsa-200606-24.xml

来源: VUPEN

名称: ADV-2006-2350

链接:http://www.frsirt.com/english/advisories/2006/2350

来源: DEBIAN

名称: DSA-1100

链接:http://www.debian.org/security/2006/dsa-1100

来源: SECUNIA

名称: 20689

链接:http://secunia.com/advisories/20689

来源: SECUNIA

名称: 20688

链接:http://secunia.com/advisories/20688

来源: SECUNIA

名称: 20665

链接:http://secunia.com/advisories/20665

来源: MANDRIVA

名称: MDKSA-2006:109

链接:http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:109

来源: UBUNTU

名称: USN-300-1

链接:http://www.ubuntulinux.org/support/documentation/usn/usn-300-1

来源: SUSE

名称: SUSE-SR:2006:015

链接:http://www.novell.com/linux/security/advisories/2006_38_security.html

来源: SECTRACK

名称: 1016313

链接:http://securitytracker.com/id?1016313

来源: SECUNIA

名称: 20899

链接:http://secunia.com/advisories/20899

来源: SECUNIA

名称: 20844

链接:http://secunia.com/advisories/20844

来源: SECUNIA

名称: 20826

链接:http://secunia.com/advisories/20826

来源: XF

名称: wvware-wv2-word-overflow(27184)

链接:http://xforce.iss.net/xforce/xfdb/27184

来源: MANDRIVA

名称: MDKSA-2006:109

链接:http://www.mandriva.com/security/advisories?name=MDKSA-2006:109

来源: sourceforge.net

链接:http://sourceforge.net/project/shownotes.php?group_id=10501&release_id=424094

受影响实体

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享