SUSE-SU-2015:1378-1
Dashboard / Vulnerabilities / SUSE-SU-2015:1378-1
SUSE-SU-2015:1378-1
Summary: Security update for libwmf
Details: libwmf was updated to fix four security issues. These security issues were fixed: - CVE-2015-4588: Heap-based buffer overflow in the DecodeImage function allowed remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted 'run-length count' in an image in a WMF file (bsc#933109). - CVE-2015-0848: Heap-based buffer overflow allowed remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted BMP image (bsc#933109). - CVE-2015-4696: Use-after-free vulnerability allowed remote attackers to cause a denial of service (crash) via a crafted WMF file to the (1) wmf2gd or (2) wmf2eps command (bsc#936062). - CVE-2015-4695: meta.h allowed remote attackers to cause a denial of service (out-of-bounds read) via a crafted WMF file (bsc#936058).
References: https://www.suse.com/support/update/announcement/2015/suse-su-20151378-1/, https://bugzilla.suse.com/831299, https://bugzilla.suse.com/933109, https://bugzilla.suse.com/936058, https://bugzilla.suse.com/936062, https://www.suse.com/security/cve/CVE-2015-0848, https://www.suse.com/security/cve/CVE-2015-4588, https://www.suse.com/security/cve/CVE-2015-4695, https://www.suse.com/security/cve/CVE-2015-4696
Affected packages
Package
Name: libwmf
Purl: pkg:rpm/suse/libwmf&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2011%20SP3
Affected ranges
Type: ECOSYSTEM
Events:
