openSUSE 10 Security Update : wv (wv-2279)

medium Nessus Plugin ID 27479

Synopsis

The remote openSUSE host is missing a security update.

Description

Two integer overflows were found in the Microsoft Word converter library 'wv', which could potentially be used to crash programs using this library or to even execute code.

- A LVL Count Integer Overflow Vulnerability was fixed.

- A LFO Count Integer Overflow Vulnerability was fixed.

Both problems have been assigned the Mitre CVE ID CVE-2006-4513.

Solution

Update the affected wv package.

Plugin Details

Severity: Medium

ID: 27479

File Name: suse_wv-2279.nasl

Version: 1.13

Type: local

Agent: unix

Published: 10/17/2007

Updated: 1/14/2021

Supported Sensors: Continuous Assessment, Frictionless Assessment Agent, Frictionless Assessment AWS, Frictionless Assessment Azure, Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 5.5

CVSS v2

Risk Factor: Medium

Base Score: 5.1

Vector: CVSS2#AV:N/AC:H/Au:N/C:P/I:P/A:P

Vulnerability Information

CPE: cpe:/o:novell:opensuse:10.1, p-cpe:/a:novell:opensuse:wv

Required KB Items: Host/local_checks_enabled, Host/SuSE/release, Host/SuSE/rpm-list, Host/cpu

Patch Publication Date: 11/16/2006

Reference Information

CVE: CVE-2006-4513