Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2015-4588

Опубликовано: 01 июн. 2015
Источник: redhat
CVSS2: 6.8
EPSS Низкий

Описание

Heap-based buffer overflow in the DecodeImage function in libwmf 0.2.8.4 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted "run-length count" in an image in a WMF file.

It was discovered that libwmf did not correctly process certain WMF (Windows Metafiles) with embedded BMP images. By tricking a victim into opening a specially crafted WMF file in an application using libwmf, a remote attacker could possibly use this flaw to execute arbitrary code with the privileges of the user running the application.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5libwmfWill not fix
Red Hat Enterprise Linux 6libwmfFixedRHSA-2015:191720.10.2015
Red Hat Enterprise Linux 7libwmfFixedRHSA-2015:191720.10.2015

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-122
https://bugzilla.redhat.com/show_bug.cgi?id=1272993libwmf: heap overflow within the RLE decoding of embedded BMP images

EPSS

Процентиль: 91%
0.07339
Низкий

6.8 Medium

CVSS2

Связанные уязвимости

ubuntu
около 10 лет назад

Heap-based buffer overflow in the DecodeImage function in libwmf 0.2.8.4 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted "run-length count" in an image in a WMF file.

nvd
около 10 лет назад

Heap-based buffer overflow in the DecodeImage function in libwmf 0.2.8.4 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted "run-length count" in an image in a WMF file.

debian
около 10 лет назад

Heap-based buffer overflow in the DecodeImage function in libwmf 0.2.8 ...

github
больше 3 лет назад

Heap-based buffer overflow in the DecodeImage function in libwmf 0.2.8.4 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted "run-length count" in an image in a WMF file.

suse-cvrf
около 10 лет назад

Security update for libwmf

EPSS

Процентиль: 91%
0.07339
Низкий

6.8 Medium

CVSS2