Name | CVE-2004-0645 |
Description | Buffer overflow in the wvHandleDateTimePicture function in wv library (wvWare) 0.7.4 through 0.7.6 and 1.0.0 allows remote attackers to execute arbitrary code via a document with a long DateTime field. |
Source | CVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) |
References | DSA-550-1, DSA-579-1 |
Debian Bugs | 264972 |
Vulnerable and fixed packages
The table below lists information on source packages.
Source Package | Release | Version | Status |
---|
abiword (PTS) | jessie | 3.0.0-8 | fixed |
| stretch | 3.0.2-2+deb9u2 | fixed |
| buster | 3.0.2-8 | fixed |
| bullseye | 3.0.4~dfsg-3 | fixed |
| bookworm | 3.0.5~dfsg-3.2 | fixed |
| sid, trixie | 3.0.6~dfsg-1 | fixed |
wv (PTS) | jessie | 1.2.9-4.1 | fixed |
| buster, bullseye, stretch | 1.2.9-4.2 | fixed |
| bookworm | 1.2.9-5 | fixed |
| sid, trixie | 1.2.9-8 | fixed |
The information below is based on the following data on fixed versions.
Notes
fixed version of abiword based on http://xforce.iss.net/xforce/xfdb/16660