漏洞信息详情
wv2 整数溢出漏洞
- CNNVD编号:CNNVD-200606-300
- 危害等级: 中危
- CVE编号:
CVE-2006-2197
- 漏洞类型:
数字错误
- 发布时间:
2006-06-15
- 威胁类型:
远程
- 更新时间:
2006-09-22
- 厂 商:
wvware - 漏洞来源:
The vendor disclos… -
漏洞简介
wv2 存在整数溢出,攻击者可能通过特制的Microsoft Word 文档上下文依赖来执行任意代码。
漏洞公告
目前厂商已经发布了相关补丁,请到厂商的主页下载:
wvWare wv2 0.2.2
Debian libwv2-1_0.2.2-1sarge1_alpha.deb
http://security.debian.org/pool/updates/main/w/wv2/libwv2-1_0.2.2-1sar ge1_alpha.deb
Debian libwv2-1_0.2.2-1sarge1_alpha.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/w/wv2/libwv2-1_0.2.2-1sar ge1_alpha.deb
Debian libwv2-1_0.2.2-1sarge1_amd64.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/w/wv2/libwv2-1_0.2.2-1sar ge1_amd64.deb
Debian libwv2-1_0.2.2-1sarge1_arm.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/w/wv2/libwv2-1_0.2.2-1sar ge1_arm.deb
Debian libwv2-1_0.2.2-1sarge1_hppa.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/w/wv2/libwv2-1_0.2.2-1sar ge1_hppa.deb
Debian libwv2-1_0.2.2-1sarge1_i386.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/w/wv2/libwv2-1_0.2.2-1sar ge1_i386.deb
Debian libwv2-1_0.2.2-1sarge1_ia64.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/w/wv2/libwv2-1_0.2.2-1sar ge1_ia64.deb
Debian libwv2-1_0.2.2-1sarge1_m68k.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/w/wv2/libwv2-1_0.2.2-1sar ge1_m68k.deb
Debian libwv2-1_0.2.2-1sarge1_mips.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/w/wv2/libwv2-1_0.2.2-1sar ge1_mips.deb
Debian libwv2-1_0.2.2-1sarge1_mipsel.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/w/wv2/libwv2-1_0.2.2-1sar ge1_mipsel.deb
Debian libwv2-1_0.2.2-1sarge1_powerpc.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/w/wv2/libwv2-1_0.2.2-1sar ge1_powerpc.deb
Debian libwv2-1_0.2.2-1sarge1_s390.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/w/wv2/libwv2-1_0.2.2-1sar ge1_s390.deb
Debian libwv2-1_0.2.2-1sarge1_sparc.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/w/wv2/libwv2-1_0.2.2-1sar ge1_sparc.deb
Debian libwv2-dev_0.2.2-1sarge1_alpha.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/w/wv2/libwv2-dev_0.2.2-1s arge1_alpha.deb
Debian libwv2-dev_0.2.2-1sarge1_amd64.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/w/wv2/libwv2-dev_0.2.2-1s arge1_amd64.deb
Debian libwv2-dev_0.2.2-1sarge1_arm.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/w/wv2/libwv2-dev_0.2.2-1s arge1_arm.deb
Debian libwv2-dev_0.2.2-1sarge1_hppa.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/w/wv2/libwv2-dev_0.2.2-1s arge1_hppa.deb
Debian libwv2-dev_0.2.2-1sarge1_ia64.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/w/wv2/libwv2-dev_0.2.2-1s arge1_ia64.deb
Debian libwv2-dev_0.2.2-1sarge1_m68k.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/w/wv2/libwv2-dev_0.2.2-1s arge1_m68k.deb
Debian libwv2-dev_0.2.2-1sarge1_mips.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/w/wv2/libwv2-dev_0.2.2-1s arge1_mips.deb
Debian libwv2-dev_0.2.2-1sarge1_mipsel.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/w/wv2/libwv2-dev_0.2.2-1s arge1_mipsel.deb
Debian libwv2-dev_0.2.2-1sarge1_powerpc.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/w/wv2/libwv2-dev_0.2.2-1s arge1_powerpc.deb
Debian libwv2-dev_0.2.2-1sarge1_s390.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/w/wv2/libwv2-dev_0.2.2-1s arge1_s390.deb
Debian libwv2-dev_0.2.2-1sarge1_sparc.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/w/wv2/libwv2-dev_0.2.2-1s arge1_sparc.deb
Mandriva lib64wv2_1-0.2.2-3.1.20060mdk.x86_64.rpm
Mandriva Linux 2006.0/X86_64:
http://wwwnew.mandriva.com/en/downloads/
Mandriva libwv2_1-0.2.2-3.1.20060mdk.i586.rpm
Mandriva Linux 2006.0:
h
参考网址
来源: BID
名称: 18437
链接:http://www.securityfocus.com/bid/18437
来源: GENTOO
名称: GLSA-200606-24
链接:http://www.gentoo.org/security/en/glsa/glsa-200606-24.xml
来源: VUPEN
名称: ADV-2006-2350
链接:http://www.frsirt.com/english/advisories/2006/2350
来源: DEBIAN
名称: DSA-1100
链接:http://www.debian.org/security/2006/dsa-1100
来源: SECUNIA
名称: 20689
链接:http://secunia.com/advisories/20689
来源: SECUNIA
名称: 20688
链接:http://secunia.com/advisories/20688
来源: SECUNIA
名称: 20665
链接:http://secunia.com/advisories/20665
来源: MANDRIVA
名称: MDKSA-2006:109
链接:http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:109
来源: UBUNTU
名称: USN-300-1
链接:http://www.ubuntulinux.org/support/documentation/usn/usn-300-1
来源: SUSE
名称: SUSE-SR:2006:015
链接:http://www.novell.com/linux/security/advisories/2006_38_security.html
来源: SECTRACK
名称: 1016313
链接:http://securitytracker.com/id?1016313
来源: SECUNIA
名称: 20899
链接:http://secunia.com/advisories/20899
来源: SECUNIA
名称: 20844
链接:http://secunia.com/advisories/20844
来源: SECUNIA
名称: 20826
链接:http://secunia.com/advisories/20826
来源: XF
名称: wvware-wv2-word-overflow(27184)
链接:http://xforce.iss.net/xforce/xfdb/27184
来源: MANDRIVA
名称: MDKSA-2006:109
链接:http://www.mandriva.com/security/advisories?name=MDKSA-2006:109
来源: sourceforge.net
链接:http://sourceforge.net/project/shownotes.php?group_id=10501&release_id=424094