Lucene search

K
kasperskyKaspersky LabKLA10239
HistoryFeb 12, 2007 - 12:00 a.m.

KLA10239 Multiple vulnerabilities in KIWI CatTools

2007-02-1200:00:00
Kaspersky Lab
threats.kaspersky.com
31

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

AI Score

7.3

Confidence

Low

EPSS

0.023

Percentile

89.6%

A buffer overflow was found in Kingsoft Writer. By exploiting this vulnerability malicious users can execute arbitrary code. This vulnerability can be exploited remotely via a specially designed WPS file. Below is a complete list of vulnerabilities

  1. A directory traversal vulnerability can be exploited remotely via a specially designed pathname;
  2. Weak encryption of sensitive information can be exploited locally via decryption.

Original advisories

Related products

Kiwi-CatTools

CVE list

CVE-2007-0889 warning

CVE-2007-0888 critical

Solution

Update to latest version

Impacts

  • OSI

Obtain sensitive information. Exploitation of vulnerabilities with this impact can lead to capturing by abuser information, critical for user or system.

  • WLF

Write Local Files. Exploitation of vulnerabilities with this impact can lead to writing into some inaccessible files. Files that can be read depends on concrete program errors.

  • RLF

Read Local Files. Exploitation of vulnerabilities with this impact can lead to reading some inaccessible files. Files that can be read depends on conсrete program errors.

Affected Products

  • Kiwi CatTools versions 3.1.9 and earlier

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

AI Score

7.3

Confidence

Low

EPSS

0.023

Percentile

89.6%