CVE-2014-8123

Name
CVE-2014-8123
Description
Buffer overflow in the bGetPPS function in wordole.c in Antiword 0.37 allows remote attackers to cause a denial of service (crash) via a crafted document.
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
Exploit http://www.openwall.com/lists/oss-security/2014/12/02/1
Exploit http://www.openwall.com/lists/oss-security/2014/12/01/4
BID http://www.securityfocus.com/bid/71386

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:antiword_project:antiword:*:*:*:*:*:*:*:* antiword >= None <= 0.37

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
antiword 3.14-community 0.37-r4 Michael Mason <ms13sp@gmail.com> possibly vulnerable
antiword 3.11-main 0.37-r3 Michael Mason <ms13sp@gmail.com> possibly vulnerable
antiword 3.15-community 0.37-r4 Michael Mason <ms13sp@gmail.com> possibly vulnerable
antiword 3.16-community 0.37-r4 Michael Mason <ms13sp@gmail.com> possibly vulnerable
antiword 3.17-community 0.37-r5 Michael Mason <ms13sp@gmail.com> fixed
antiword edge-community 0.37-r6 Michael Mason <ms13sp@gmail.com> fixed
antiword 3.18-community 0.37-r6 Michael Mason <ms13sp@gmail.com> fixed