CVE-2005-1678

Groove Virtual Office before 3.1 build 2338, before 3.1a build 2364, and Groove Workspace before 2.5n build 1871 does not properly display file extensions on attached or embedded files in a compound document, which may allow remote attackers to trick users into executing malicious code.
References
Link Resource
http://www.kb.cert.org/vuls/id/JGEI-6BCRD6 Third Party Advisory US Government Resource
http://www.kb.cert.org/vuls/id/232232 Third Party Advisory US Government Resource
http://secunia.com/advisories/15421 Patch Vendor Advisory
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:groove:groove_workspace:*:*:*:*:*:*:*:*
cpe:2.3:a:groove:virtual_office:*:*:*:*:*:*:*:*
cpe:2.3:a:groove:virtual_office:*:*:*:*:*:*:*:*

Information

Published : 2005-05-19 21:00

Updated : 2008-09-05 13:49


NVD link : CVE-2005-1678

Mitre link : CVE-2005-1678


JSON object : View

Advertisement

dedicated server usa

Products Affected

groove

  • groove_workspace
  • virtual_office