Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-13999

Опубликовано: 15 июн. 2020
Источник: redhat
CVSS3: 5.5

Описание

ScaleViewPortExtEx in libemf.cpp in libEMF (aka ECMA-234 Metafile Library) 1.0.12 allows an integer overflow and denial of service via a crafted EMF file.

Отчет

libEMF is a C/C++ library which provides a drawing toolkit based on ECMA-234. The general purpose of this library is to create vector graphics files on POSIX systems which can be imported into OpenOffice.org or LibreOffice. Programs compiled with libEMF, output ECMA-234 graphics files locally which can be then imported into desktop applications. Therefore this vulnerability can only be triggered via maliciously written applications compiled with libEMF.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6libEMFOut of support scope

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-190
https://bugzilla.redhat.com/show_bug.cgi?id=1850254libemf: Integer overflow which could result in denial of service

5.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.5
ubuntu
больше 5 лет назад

ScaleViewPortExtEx in libemf.cpp in libEMF (aka ECMA-234 Metafile Library) 1.0.12 allows an integer overflow and denial of service via a crafted EMF file.

CVSS3: 5.5
nvd
больше 5 лет назад

ScaleViewPortExtEx in libemf.cpp in libEMF (aka ECMA-234 Metafile Library) 1.0.12 allows an integer overflow and denial of service via a crafted EMF file.

CVSS3: 5.5
debian
больше 5 лет назад

ScaleViewPortExtEx in libemf.cpp in libEMF (aka ECMA-234 Metafile Libr ...

suse-cvrf
больше 3 лет назад

Security update for libEMF

suse-cvrf
больше 3 лет назад

Security update for libEMF

5.5 Medium

CVSS3