Описание
Security update for libwmf
libwmf was updated to fix five security issues.
These security issues were fixed:
- CVE-2009-1364: Fixed realloc return value usage (bsc#495842, bnc#831299)
- CVE-2015-0848: Heap overflow on libwmf0.2-7 (bsc#933109)
- CVE-2015-4588: DecodeImage() did not check that the run-length 'count' fits into the total size of the image, which could lead to a heap-based buffer overflow (bsc#933109)
- CVE-2015-4695: meta_pen_create heap buffer over read (bsc#936058)
- CVE-2015-4696: Use after free (bsc#936062)
Список пакетов
SUSE Linux Enterprise Desktop 12
SUSE Linux Enterprise Software Development Kit 12
SUSE Linux Enterprise Workstation Extension 12
Ссылки
- Link for SUSE-SU-2015:1484-1
- E-Mail link for SUSE-SU-2015:1484-1
- SUSE Security Ratings
- SUSE Bug 495842
- SUSE Bug 831299
- SUSE Bug 933109
- SUSE Bug 936058
- SUSE Bug 936062
- SUSE CVE CVE-2009-1364 page
- SUSE CVE CVE-2015-0848 page
- SUSE CVE CVE-2015-4588 page
- SUSE CVE CVE-2015-4695 page
- SUSE CVE CVE-2015-4696 page
Описание
Use-after-free vulnerability in the embedded GD library in libwmf 0.2.8.4 allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted WMF file.
Затронутые продукты
Ссылки
- CVE-2009-1364
- SUSE Bug 495842
Описание
Heap-based buffer overflow in libwmf 0.2.8.4 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted BMP image.
Затронутые продукты
Ссылки
- CVE-2015-0848
- SUSE Bug 933109
Описание
Heap-based buffer overflow in the DecodeImage function in libwmf 0.2.8.4 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted "run-length count" in an image in a WMF file.
Затронутые продукты
Ссылки
- CVE-2015-4588
- SUSE Bug 933109
Описание
meta.h in libwmf 0.2.8.4 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted WMF file.
Затронутые продукты
Ссылки
- CVE-2015-4695
- SUSE Bug 936058
Описание
Use-after-free vulnerability in libwmf 0.2.8.4 allows remote attackers to cause a denial of service (crash) via a crafted WMF file to the (1) wmf2gd or (2) wmf2eps command.
Затронутые продукты
Ссылки
- CVE-2015-4696
- SUSE Bug 936062