Vulnerabilities > CVE-2004-0645

047910
CVSS 10.0 - CRITICAL
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
COMPLETE
Integrity impact
COMPLETE
Availability impact
COMPLETE
network
low complexity
abisource
wvware
critical
nessus

Summary

Buffer overflow in the wvHandleDateTimePicture function in wv library (wvWare) 0.7.4 through 0.7.6 and 1.0.0 allows remote attackers to execute arbitrary code via a document with a long DateTime field.

Nessus

  • NASL familyGentoo Local Security Checks
    NASL idGENTOO_GLSA-200407-11.NASL
    descriptionThe remote host is affected by the vulnerability described in GLSA-200407-11 (wv: Buffer overflow vulnerability) A use of strcat without proper bounds checking leads to an exploitable buffer overflow. The vulnerable code is executed when wv encounters an unrecognized token, so a specially crafted file, loaded in wv, can trigger the vulnerable code and execute its own arbitrary code. This exploit is only possible when the user loads the document into HTML view mode. Impact : By inducing a user into running wv on a special file, an attacker can execute arbitrary code with the permissions of the user running the vulnerable program. Workaround : Users should not view untrusted documents with wvHtml or applications using wv. When loading an untrusted document in an application using the wv library, make sure HTML view is disabled.
    last seen2020-06-01
    modified2020-06-02
    plugin id14544
    published2004-08-30
    reporterThis script is Copyright (C) 2004-2019 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/14544
    titleGLSA-200407-11 : wv: Buffer overflow vulnerability
  • NASL familyDebian Local Security Checks
    NASL idDEBIAN_DSA-579.NASL
    descriptionA buffer overflow vulnerability has been discovered in the wv library, used for converting and previewing word documents. On exploitation an attacker could execute arbitrary code with the privileges of the user running the vulnerable application.
    last seen2020-06-01
    modified2020-06-02
    plugin id15677
    published2004-11-10
    reporterThis script is Copyright (C) 2004-2019 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/15677
    titleDebian DSA-579-1 : abiword - buffer overflow
  • NASL familyMandriva Local Security Checks
    NASL idMANDRAKE_MDKSA-2004-077.NASL
    descriptioniDefense discovered a buffer overflow vulnerability in the wv package which could allow an attacker to execute arbitrary code with the privileges of the user running the vulnerable application. The updated packages are patched to protect against this problem.
    last seen2020-06-01
    modified2020-06-02
    plugin id14175
    published2004-07-31
    reporterThis script is Copyright (C) 2004-2019 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/14175
    titleMandrake Linux Security Advisory : wv (MDKSA-2004:077)
  • NASL familyDebian Local Security Checks
    NASL idDEBIAN_DSA-550.NASL
    descriptioniDEFENSE discovered a buffer overflow in the wv library, used to convert and preview Microsoft Word documents. An attacker could create a specially crafted document that could lead wvHtml to execute arbitrary code on the victims machine.
    last seen2020-06-01
    modified2020-06-02
    plugin id15387
    published2004-09-29
    reporterThis script is Copyright (C) 2004-2019 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/15387
    titleDebian DSA-550-1 : wv - buffer overflow