CVE-2005-1678

Groove Virtual Office before 3.1 build 2338, before 3.1a build 2364, and Groove Workspace before 2.5n build 1871 does not properly display file extensions on attached or embedded files in a compound document, which may allow remote attackers to trick users into executing malicious code.
References
Link Resource
http://secunia.com/advisories/15421 Patch Vendor Advisory
http://www.kb.cert.org/vuls/id/232232 Third Party Advisory US Government Resource
http://www.kb.cert.org/vuls/id/JGEI-6BCRD6 Third Party Advisory US Government Resource
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:groove:groove_workspace:*:*:*:*:*:*:*:*
cpe:2.3:a:groove:virtual_office:*:*:*:*:*:*:*:*
cpe:2.3:a:groove:virtual_office:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2005-05-20 04:00

Updated : 2024-02-04 16:52


NVD link : CVE-2005-1678

Mitre link : CVE-2005-1678

CVE.ORG link : CVE-2005-1678


JSON object : View

Products Affected

groove

  • groove_workspace
  • virtual_office