VDB
Sign up
CRITICAL9.8

GHSA-2j6v-xpf3-xvrv

Use of Externally-Controlled Format String in wire-avs

Quick fix

GHSA-2j6v-xpf3-xvrv — com.wire:avs: upgrade to the fixed version with the command below.

# pom.xml: bump <version>7.1.12</version> for com.wire:avs

Details

### Impact A remote format string vulnerability allowed an attacker to cause a denial of service or possibly execute arbitrary code.

### Patches * The issue has been fixed in wire-avs 7.1.12 and is already included on all Wire products (currently used version is 8.0.x)

### Workarounds * No workaround known

### References * Fixed in commit https://github.com/wireapp/wire-avs/commit/40d373ede795443ae6f2f756e9fb1f4f4ae90bbe

### For more information

If you have any questions or comments about this advisory feel free to email us at [vulnerability-report@wire.com](mailto:vulnerability-report@wire.com)

Are you affected?

Enter the version of the package you're using.

Affected packages

Maven/com.wire:avs
Introduced in: 0Fixed in: 7.1.12
Fix# pom.xml: bump <version>7.1.12</version> for com.wire:avs

References