Executive Summary
Summary | |
---|---|
Title | New abiword packages fix arbitrary code execution |
Informations | |||
---|---|---|---|
Name | DSA-579 | First vendor Publication | 2004-11-01 |
Vendor | Debian | Last vendor Modification | 2004-11-01 |
Severity (Vendor) | N/A | Revision | 1 |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:N/AC:L/Au:N/C:C/I:C/A:C) | |||
---|---|---|---|
Cvss Base Score | 10 | Attack Range | Network |
Cvss Impact Score | 10 | Attack Complexity | Low |
Cvss Expoit Score | 10 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
A buffer overflow vulnerability has been disovered in the wv library, used for converting and previewing word documents. On exploition an attacker could execute arbitrary code with the privileges of the user running the vulnerable application. For the stable distribution (woody) this problem has been fixed in version 1.0.2+cvs.2002.06.05-1woody2. The package in the unstable distribution (sid) is not affected. We recommend that you upgrade your abiword package. |
Original Source
Url : http://www.debian.org/security/2004/dsa-579 |
CPE : Common Platform Enumeration
Type | Description | Count |
---|---|---|
Application | 5 | |
Application | 4 |
OpenVAS Exploits
Date | Description |
---|---|
2008-09-24 | Name : Gentoo Security Advisory GLSA 200407-11 (app-text/wv) File : nvt/glsa_200407_11.nasl |
2008-01-17 | Name : Debian Security Advisory DSA 550-1 (wv) File : nvt/deb_550_1.nasl |
2008-01-17 | Name : Debian Security Advisory DSA 579-1 (abiword) File : nvt/deb_579_1.nasl |
Open Source Vulnerability Database (OSVDB)
Id | Description |
---|---|
7761 | wv Library Document DateTime Field Overflow |
Nessus® Vulnerability Scanner
Date | Description |
---|---|
2004-11-10 | Name : The remote Debian host is missing a security-related update. File : debian_DSA-579.nasl - Type : ACT_GATHER_INFO |
2004-09-29 | Name : The remote Debian host is missing a security-related update. File : debian_DSA-550.nasl - Type : ACT_GATHER_INFO |
2004-08-30 | Name : The remote Gentoo host is missing one or more security-related patches. File : gentoo_GLSA-200407-11.nasl - Type : ACT_GATHER_INFO |
2004-07-31 | Name : The remote Mandrake Linux host is missing one or more security updates. File : mandrake_MDKSA-2004-077.nasl - Type : ACT_GATHER_INFO |
Alert History
Date | Informations |
---|---|
2014-02-17 11:33:33 |
|