Description
wire-avs is the audio visual signaling (AVS) component of Wire, an open-source messenger. A remote format string vulnerability in versions prior to 7.1.12 allows an attacker to cause a denial of service or possibly execute arbitrary code. The issue has been fixed in wire-avs 7.1.12. There are currently no known workarounds.
Remediation
References
https://github.com/wireapp/wire-avs/commit/40d373ede795443ae6f2f756e9fb1f4f4ae90bbe
https://github.com/wireapp/wire-avs/security/advisories/GHSA-2j6v-xpf3-xvrv
Related Vulnerabilities
CVE-2020-28496 Vulnerability in maven package org.webjars.npm:three
CVE-2021-37695 Vulnerability in npm package ckeditor4
CVE-2022-24615 Vulnerability in maven package net.lingala.zip4j:zip4j
CVE-2020-1960 Vulnerability in maven package org.apache.flink:flink-metrics-jmx
CVE-2023-37895 Vulnerability in maven package org.apache.jackrabbit:jackrabbit-standalone