<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "http://bugs.gentoo.org/bugzilla.dtd">

<bugzilla version="2.22.7"
          urlbase="http://bugs.gentoo.org/"
          maintainer="bugzilla@gentoo.org"
>

    <bug>
          <bug_id>56595</bug_id>
          
          <creation_ts>2004-07-10 03:24 0000</creation_ts>
          <short_desc>app-text/wv-1.0.0 - Buffer Overflow Vulnerability</short_desc>
          <delta_ts>2004-07-14 04:14:38 0000</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>Gentoo Linux</product>
          <component>Security</component>
          <version>unspecified</version>
          <rep_platform>All</rep_platform>
          <op_sys>All</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          
          <status_whiteboard>B2 [glsa]</status_whiteboard>
          
          <priority>P2</priority>
          <bug_severity>normal</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          
          <everconfirmed>1</everconfirmed>
          <reporter>carlo@gentoo.org</reporter>
          <assigned_to>security@gentoo.org</assigned_to>
          <cc>foser@gentoo.org</cc>

      

      
          <long_desc isprivate="0">
            <who>carlo@gentoo.org</who>
            <bug_when>2004-07-10 03:24:32 0000</bug_when>
            <thetext>Caol</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>carlo@gentoo.org</who>
            <bug_when>2004-07-10 03:24:32 0000</bug_when>
            <thetext>Caolán McNamara and Dom Lachowiczs wv library has been found to contain
a buffer overflow condition that can be exploited through a specially
crafted document.

If an attacker can convince a user to open an exploit document in HTML
mode using an application that builds upon the wv library, it is
possible for the attacker to execute arbitrary code under the privileges
of that user.

iDEFENSE has confirmed the existence of this vulnerability in version
0.7.4, and a slight variant of this vulnerability in versions 0.7.5,
0.7.6 and 1.0.0.

http://www.idefense.com/application/poi/display?id=115&amp;type=vulnerabilities


I&apos;m not sure, who&apos;s the maintainer in this case - metadata.xml is missing.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>carlo@gentoo.org</who>
            <bug_when>2004-07-10 03:27:40 0000</bug_when>
            <thetext>forgot the patch url mentioned in the advisory: http://www.abisource.com/bonsai/cvsview2.cgi?diff_mode=context&amp;whitespace_mode=show&amp;root=/cvsroot&amp;subdir=wv&amp;command=DIFF_FRAMESET&amp;root=/cvsroot&amp;file=field.c&amp;rev1=1.19&amp;rev2=1.20
</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2004-07-10 03:57:26 0000</bug_when>
            <thetext>Marinus you have committed the last few new versions will you commit a patched ebuild?

Also you might want to correct HOMEPAGE to point to the SF page.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>foser@gentoo.org</who>
            <bug_when>2004-07-12 09:41:45 0000</bug_when>
            <thetext>added the patch + minor USE fix to the ebuild. Bumped to 1.0.0-r1 all stable (the fixes were minor and i guess this needs to go in).</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>koon@gentoo.org</who>
            <bug_when>2004-07-12 13:06:57 0000</bug_when>
            <thetext>Ready for a GLSA</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>koon@gentoo.org</who>
            <bug_when>2004-07-14 04:14:38 0000</bug_when>
            <thetext>GLSA 200407-11</thetext>
          </long_desc>
      
    </bug>

</bugzilla>