Secunia Logo
Netsikker nu! 2008
 
CVE Reference: CVE-2007-0002
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2007-0002

Description:
Multiple heap-based buffer overflows in WordPerfect Document importer/exporter (libwpd) before 0.8.9 allow user-assisted remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted WordPerfect file in which values to loop counters are not properly handled in the (1) WP3TablesGroup::_readContents and (2) WP5DefinitionGroup_DefineTablesSubGroup::WP5DefinitionGroup_DefineTablesSubGroup functions. NOTE: the integer overflow has been split into CVE-2007-1466.

CVE Status:
Candidate

References:

UBUNTU
  http://www.ubuntu.com/usn/usn-437-1

SUSE
  http://lists.suse.com/archive/suse-security-announce/2007-Mar/0007.html

SUNALERT
  http://sunsolve.sun.com/search/document.do?assetkey=1-26-102863-1

ST
  1017789

SLACKWARE
  http://slackware.com/security/viewer.php?l=slackware-security&y=2007&m=slackware-security.399659

SAID
  Secunia Advisory: SA24573
  Secunia Advisory: SA24580
  Secunia Advisory: SA24572
  Secunia Advisory: SA24557
  Secunia Advisory: SA24507
  Secunia Advisory: SA24581
  Secunia Advisory: SA24593
  Secunia Advisory: SA24465
  Secunia Advisory: SA24794
  Secunia Advisory: SA24856
  Secunia Advisory: SA24906
  Secunia Advisory: SA24588
  Secunia Advisory: SA24613
  Secunia Advisory: SA24591

REDHAT
  http://www.redhat.com/support/errata/RHSA-2007-0055.html

MANDRIVA
  http://frontal2.mandriva.com/security/advisories?name=MDKSA-2007:063
  http://frontal2.mandriva.com/security/advisories?name=MDKSA-2007:064

IDEFENSE
  http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=490

GENTOO
  http://security.gentoo.org/glsa/glsa-200704-07.xml
  http://www.gentoo.org/security/en/glsa/glsa-200704-12.xml

FEDORA
  http://fedoranews.org/cms/node/2805

DEBIAN
  http://www.debian.org/security/2007/dsa-1268
  http://www.debian.org/security/2007/dsa-1270

CONFIRM
  http://sourceforge.net/project/shownotes.php?release_id=494122

BUGTRAQ
  http://www.securityfocus.com/archive/1/archive/1/463033/100/0/threaded

BID
  23006


Return to the previous page.