[Forgot Password]
Login  Register Subscribe

30481

 
 

423868

 
 

256040

 
 

909

 
 

199103

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

ALAS-2015-604 --- libwmf

ID: oval:org.secpod.oval:def:1200013Date: (C)2016-01-04   (M)2024-02-19
Class: PATCHFamily: unix




It was discovered that libwmf did not correctly process certain WMF with embedded BMP images. By tricking a victim into opening a specially crafted WMF file in an application using libwmf, a remote attacker could possibly use this flaw to execute arbitrary code with the privileges of the user running the application. It was discovered that libwmf did not properly process certain WMF files. By tricking a victim into opening a specially crafted WMF file in an application using libwmf, a remote attacker could possibly exploit this flaw to cause a crash or execute arbitrary code with the privileges of the user running the application. It was discovered that libwmf did not properly process certain WMF files. By tricking a victim into opening a specially crafted WMF file in an application using libwmf, a remote attacker could possibly exploit this flaw to cause a crash. The gdPngReadData function in libgd 2.0.34 allows user-assisted attackers to cause a denial of service via a crafted PNG image with truncated data, which causes an infinite loop in the png_read_info function in libpng. Buffer overflow in the gdImageStringFTEx function in gdft.c in GD Graphics Library 2.0.33 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted string with a JIS encoded font. The _gdGetColors function in gd_gd.c in PHP 5.2.11 and 5.3.x before 5.3.1, and the GD Graphics Library 2.x, does not properly verify a certain colorsTotal structure member, which might allow remote attackers to conduct buffer overflow or buffer over-read attacks via a crafted GD file, a different vulnerability than CVE-2009-3293 . NOTE: some of these details are obtained from third party information. Integer overflow in gdImageCreateTrueColor function in the GD Graphics Library before 2.0.35 allows user-assisted remote attackers to have unspecified attack vectors and impact. The gdImageCreateXbm function in the GD Graphics Library before 2.0.35 allows user-assisted remote attackers to cause a denial of service via unspecified vectors involving a gdImageCreate failure

Platform:
Amazon Linux AMI
Product:
libwmf
Reference:
ALAS-2015-604
CVE-2015-4696
CVE-2015-4695
CVE-2015-4588
CVE-2015-0848
CVE-2009-3546
CVE-2007-3473
CVE-2007-3472
CVE-2007-2756
CVE-2007-0455
CVE    9
CVE-2007-0455
CVE-2007-2756
CVE-2007-3473
CVE-2007-3472
...
CPE    2
cpe:/o:amazon:linux
cpe:/a:francis_james_franklin:libwmf

© SecPod Technologies