UbuntuUpdates.org

Package "libwmf0.2-7"

Name: libwmf0.2-7

Description:

Windows metafile conversion library

Latest version: 0.2.8.4-10.3ubuntu1.14.04.1
Release: trusty (14.04)
Level: updates
Repository: main
Head package: libwmf

Links


Download "libwmf0.2-7"


Other versions of "libwmf0.2-7" in Trusty

Repository Area Version
base main 0.2.8.4-10.3ubuntu1
security main 0.2.8.4-10.3ubuntu1.14.04.1

Changelog

Version: 0.2.8.4-10.3ubuntu1.14.04.1 2015-07-08 16:08:24 UTC

  libwmf (0.2.8.4-10.3ubuntu1.14.04.1) trusty-security; urgency=medium

  * SECURITY UPDATE: denial of service and possible code execution
    - d/p/CVE-2015-0848_CVE-2015-4588_CVE-2015-4695_CVE-2015-4696.patch:
      check bounds and handle unexpected pixel depth in src/player/meta.h,
      src/ipa/ipa.h, src/ipa/ipa/bmp.h.
    - CVE-2015-0848
    - CVE-2015-4588
    - CVE-2015-4685
    - CVE-2015-4696

 -- Marc Deslauriers Tue, 07 Jul 2015 14:40:31 -0400

CVE-2015-0848 Heap-based buffer overflow in libwmf 0.2.8.4 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a cr
CVE-2015-4588 Heap-based buffer overflow in the DecodeImage function in libwmf 0.2.8.4 allows remote attackers to cause a denial of service (crash) or possibly exe
CVE-2015-4695 meta.h in libwmf 0.2.8.4 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted WMF file.
CVE-2015-4696 Use-after-free vulnerability in libwmf 0.2.8.4 allows remote attackers to cause a denial of service (crash) via a crafted WMF file to the (1) wmf2gd
CVE-2015-4685 RESERVED



About   -   Send Feedback to @ubuntu_updates