CVE Database
/

CVE-2006-4513

Back to search

CVE-2006-4513

Published: Oct 28, 2006

Modified: Aug 7, 2024

PUBLISHED

Description

Multiple integer overflows in the WV library in wvWare (formerly mswordview) before 1.2.3, as used by AbiWord, KWord, and possibly other products, allow user-assisted remote attackers to execute arbitrary code via a crafted Microsoft Word (DOC) file that produces (1) large LFO clfolvl values in the wvGetLFO_records function or (2) a large LFO nolfo value in the wvGetFLO_PLF function.

VendorProductVersions

n/a

n/a

affected
n/a

References

ADV-2006-4221
vdb-entry
x_refsource_VUPEN
1017126
vdb-entry
x_refsource_SECTRACK
22705
third-party-advisory
x_refsource_SECUNIA
SUSE-SR:2006:028
vendor-advisory
x_refsource_SUSE
GLSA-200612-01
vendor-advisory
x_refsource_GENTOO
MDKSA-2006:202
vendor-advisory
x_refsource_MANDRIVA
23335
third-party-advisory
x_refsource_SECUNIA
22680
third-party-advisory
x_refsource_SECUNIA
23273
third-party-advisory
x_refsource_SECUNIA
22595
third-party-advisory
x_refsource_SECUNIA
20761
vdb-entry
x_refsource_BID
wvware-lfo-lvl-overflow(29833)
vdb-entry
x_refsource_XF
USN-374-1
vendor-advisory
x_refsource_UBUNTU

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now