copyright | disclaimer | privacy | contact  
Australia's Leading Computer Emergency Response Team
Search this site

On this site

 > About AusCERT
 > Membership
 > Contact Us
 > PKI Services
 > Publications
 > Sec. Bulletins
 > Conferences
 > News & Media
 > Services
 > Web Log
 > Site Map
 > Site Help
 > Member login


ESB-2006.0418 -- [UNIX/Linux][Debian] -- New wv2 packages fix integer overflow

Date: 15 June 2006

Click here for printable version
Click here for PGP verifiable version
Hash: SHA1

             AUSCERT External Security Bulletin Redistribution

                   ESB-2006.0418 -- [UNIX/Linux][Debian]
                   New wv2 packages fix integer overflow
                               15 June 2006


        AusCERT Security Bulletin Summary

Product:              wv library
Publisher:            Debian
Operating System:     Debian GNU/Linux 3.1
                      UNIX variants (UNIX, Linux, OSX)
Impact:               Execute Arbitrary Code/Commands
Access:               Remote/Unauthenticated
CVE Names:            CVE-2006-2197

Original Bulletin:

Comment: This advisory references vulnerabilities in products which run on
         platforms other than Debian. It is recommended that administrators
         using the wv library check for an updated version of the software
         for their operating system.

- --------------------------BEGIN INCLUDED TEXT--------------------

Hash: SHA1

- - --------------------------------------------------------------------------
Debian Security Advisory DSA 1100-1                                       Martin Schulze
June 15th, 2006               
- - --------------------------------------------------------------------------

Package        : wv2
Vulnerability  : integer overflow
Problem type   : local (remote)
Debian-specific: no
CVE ID         : CVE-2006-2197

A boundary checking error has been discovered in wv2, a library for
accessing Microsoft Word documents, which can lead to an integer
overflow induced by processing word files.

The old stable distribution (woody) does not contain wv2 packages.

For the stable distribution (sarge) this problem has been fixed in
version 0.2.2-1sarge1

For the unstable distribution (sid) this problem will be fixed soon.

We recommend that you upgrade your libwv packages.

Upgrade Instructions
- - --------------------

wget url
        will fetch the file for you
dpkg -i file.deb
        will install the referenced file.

If you are using the apt-get package manager, use the line for
sources.list as given at the end of this advisory:

apt-get update
        will update the internal database
apt-get upgrade
        will install corrected packages

You may use an automated update by adding the resources from the
footer to the proper configuration.

Debian GNU/Linux 3.1 alias sarge
- - --------------------------------

  Source archives:
      Size/MD5 checksum:      647 1e70762ab53a672f05164a004f5c93a9
      Size/MD5 checksum:    12720 068c3fbeb3965747027fe1382dcb55a5
      Size/MD5 checksum:   855198 45fdc6df614f91e94d3b978dd8414e3b

  Alpha architecture:
      Size/MD5 checksum:   295880 44a8b7e985cf5d0076c6242dd12211d2
      Size/MD5 checksum:   183238 5d1fb1fac9d1d972e3541e5e46e0267d

  AMD64 architecture:
      Size/MD5 checksum:   243294 136d61f3757dc5e79dc51427812d5a49
      Size/MD5 checksum:   183218 67cd1e898372ceebfb0ef3b86a6cc779

  ARM architecture:
      Size/MD5 checksum:   230210 0b5de6817405b35407dd77d12fc405f4
      Size/MD5 checksum:   183242 684d3f82878ad64f9528e1924c024d1d

  Intel IA-32 architecture:
      Size/MD5 checksum:   235894 db949bdc9038c6b0302acf8e0e477b38
      Size/MD5 checksum:   182010 202a0c2946a91417bd542627e7a836f4

  Intel IA-64 architecture:
      Size/MD5 checksum:   322098 40ff1b5c6cd42743e20512a5683bfe86
      Size/MD5 checksum:   183230 8e4cd47604baaf864e5ce1dd7d2b8747

  HP Precision architecture:
      Size/MD5 checksum:   253064 99c119d4a607f4fb055642b3583aaccd
      Size/MD5 checksum:   183238 8246aabd232173a8cf2db2a87c1b6be1

  Motorola 680x0 architecture:
      Size/MD5 checksum:   219026 f843f05b4d6b28be1680ab1ea962d666
      Size/MD5 checksum:   183264 bbd4acf79208a50da1b2053c2e31ec0c

  Big endian MIPS architecture:
      Size/MD5 checksum:   215108 d1247a70a8927eae92203cb6af8ad049
      Size/MD5 checksum:   183238 0bc66cb90bceee86df3fafeda0b3a1bb

  Little endian MIPS architecture:
      Size/MD5 checksum:   211034 8d74d1043e4869f4d3def7918e62dfb8
      Size/MD5 checksum:   183234 d531933dd916dd5bf57cb58de979de74

  PowerPC architecture:
      Size/MD5 checksum:   221752 790897f6117b02e5410705647d7fa658
      Size/MD5 checksum:   183246 b8c42cb926f17f1c0ced7de85f6659f0

  IBM S/390 architecture:
      Size/MD5 checksum:   249622 fe89ae95081d62faafd1b3fc8edd286d
      Size/MD5 checksum:   183234 b2b0f8c169daf96b71f16ff0ae300380

  Sun Sparc architecture:
      Size/MD5 checksum:   229240 f0c767b5e8ec342bf043a79edf13a6ae
      Size/MD5 checksum:   183238 02fad53089315e41000c28bdda733e07

  These files will probably be moved into the stable distribution on
  its next update.

- - ---------------------------------------------------------------------------------
For apt-get: deb stable/updates main
For dpkg-ftp: dists/stable/updates/main
Mailing list:
Package info: `apt-cache show <pkg>' and<pkg>

Version: GnuPG v1.4.3 (GNU/Linux)


- --------------------------END INCLUDED TEXT--------------------

You have received this e-mail bulletin as a result of your organisation's
registration with AusCERT. The mailing list you are subscribed to is
maintained within your organisation, so if you do not wish to continue
receiving these bulletins you should contact your local IT manager. If
you do not know who that is, please send an email to
and we will forward your request to the appropriate person.

NOTE: Third Party Rights
This security bulletin is provided as a service to AusCERT's members.  As
AusCERT did not write the document quoted above, AusCERT has had no control
over its content. The decision to follow or act on information or advice
contained in this security bulletin is the responsibility of each user or
organisation, and should be considered in accordance with your organisation's
site policies and procedures. AusCERT takes no responsibility for consequences
which may arise from following or acting on information or advice contained in
this security bulletin.

NOTE: This is only the original release of the security bulletin.  It may
not be updated when updates to the original are made.  If downloading at
a later date, it is recommended that the bulletin is retrieved directly
from the author's website to ensure that the information is still current.

Contact information for the authors of the original document is included
in the Security Bulletin above.  If you have any questions or need further
information, please contact them directly.

Previous advisories and external security bulletins can be retrieved from:

If you believe that your computer system has been compromised or attacked in 
any way, we encourage you to let us know by completing the secure National IT 
Incident Reporting Form at:

Australian Computer Emergency Response Team
The University of Queensland
Qld 4072

Internet Email:
Facsimile:      (07) 3365 7031
Telephone:      (07) 3365 4417 (International: +61 7 3365 4417)
                AusCERT personnel answer during Queensland business hours
                which are GMT+10:00 (AEST).
                On call after hours for member emergencies only.