GHSA-2j6v-xpf3-xvrv
Use of Externally-Controlled Format String in wire-avs
Quick fix
GHSA-2j6v-xpf3-xvrv — com.wire:avs: upgrade to the fixed version with the command below.
# pom.xml: bump <version>7.1.12</version> for com.wire:avsDetails
### Impact A remote format string vulnerability allowed an attacker to cause a denial of service or possibly execute arbitrary code.
### Patches * The issue has been fixed in wire-avs 7.1.12 and is already included on all Wire products (currently used version is 8.0.x)
### Workarounds * No workaround known
### References * Fixed in commit https://github.com/wireapp/wire-avs/commit/40d373ede795443ae6f2f756e9fb1f4f4ae90bbe
### For more information
If you have any questions or comments about this advisory feel free to email us at [vulnerability-report@wire.com](mailto:vulnerability-report@wire.com)
Are you affected?
Enter the version of the package you're using.
Affected packages
0Fixed in: 7.1.12# pom.xml: bump <version>7.1.12</version> for com.wire:avs