Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Multiple integer overflows in the WV library in wvWare (formerly mswordview) before 1.2.3, as used by AbiWord, KWord, and possibly other products, allow user-assisted remote attackers to execute arbitrary code via a crafted Microsoft Word (DOC) file that produces (1) large LFO clfolvl values in the wvGetLFO_records function or (2) a large LFO nolfo value in the wvGetFLO_PLF function.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
wvWare多个整数溢出漏洞
Vulnerability Description
wvWare是一个用于装载和解析Microsoft Word文件的库。 WV库的实现上存在多个整数溢出漏洞,攻击者可能利用这些漏洞在用户机器上执行任意指令。 WV库在解析文档时没有检查溢出情况便使用常数乘以用户所提供的整数值: 35 int 36 wvGetLFO_records (LFO ** lfo, LFOLVL ** lfolvl, LVL ** lvl, U32 *nolfo, 37 U32 * nooflvl, U32 offset, U32 len, wvStream *fd) 38 { .
CVSS Information
N/A
Vulnerability Type
N/A