Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.51615
Category:Fedora Local Security Checks
Title:Fedora Legacy Security Advisory FLSA-2005:1906
Summary:NOSUMMARY
Description:Description:

The remote host is missing updates announced in
advisory FLSA-2005:1906.

AbiWord is a cross-platform, open-source word processor.

A buffer overflow in the wv library included in abiword allows remote
attackers to execute arbitrary code via a document with a long DateTime
field.

All users are advised to upgrade to these updated packages, which contain a
backported fix and are not vulnerable to this issue.

Fedora Legacy would like to thank Marc Deslauriers for reporting this issue,
and Dave Botsch and Marc Deslauriers and preparing updated RPMs.

Affected platforms:
Redhat 7.3
Redhat 9

Solution:
http://www.securityspace.com/smysecure/catid.html?in=FLSA-2005:1906
http://www.abisource.com/release-notes/2.0.9.phtml
http://xforce.iss.net/xforce/xfdb/16660
http://www.idefense.com/application/poi/display?id=115&type=vulnerabilities&flashstatus=true

Risk factor : Critical

CVSS Score:
10.0

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2004-0645
Conectiva Linux advisory: CLA-2004:863
http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000863
Debian Security Information: DSA-579 (Google Search)
http://www.debian.org/security/2004/dsa-579
https://bugzilla.fedora.us/show_bug.cgi?id=1906
http://security.gentoo.org/glsa/glsa-200407-11.xml
http://www.idefense.com/application/poi/display?id=115&type=vulnerabilities
http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2004:077
http://www.osvdb.org/7761
XForce ISS Database: wvware-wvhandledatetimepicture-bo(16660)
https://exchange.xforce.ibmcloud.com/vulnerabilities/16660
CopyrightCopyright (c) 2005 E-Soft Inc. http://www.securityspace.com

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.