Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2015-0848

Опубликовано: 01 июн. 2015
Источник: redhat
CVSS2: 6.8

Описание

Heap-based buffer overflow in libwmf 0.2.8.4 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted BMP image.

It was discovered that libwmf did not correctly process certain WMF (Windows Metafiles) containing BMP images. By tricking a victim into opening a specially crafted WMF file in an application using libwmf, a remote attacker could possibly use this flaw to execute arbitrary code with the privileges of the user running the application.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5libwmfWill not fix
Red Hat Enterprise Linux 6libwmfFixedRHSA-2015:191720.10.2015
Red Hat Enterprise Linux 7libwmfFixedRHSA-2015:191720.10.2015

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-122
https://bugzilla.redhat.com/show_bug.cgi?id=1227243libwmf: heap overflow when decoding BMP images

6.8 Medium

CVSS2

Связанные уязвимости

ubuntu
около 10 лет назад

Heap-based buffer overflow in libwmf 0.2.8.4 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted BMP image.

nvd
около 10 лет назад

Heap-based buffer overflow in libwmf 0.2.8.4 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted BMP image.

debian
около 10 лет назад

Heap-based buffer overflow in libwmf 0.2.8.4 allows remote attackers t ...

github
больше 3 лет назад

Heap-based buffer overflow in libwmf 0.2.8.4 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted BMP image.

suse-cvrf
около 10 лет назад

Security update for libwmf

6.8 Medium

CVSS2