You are here
Home > Preporuke > Ranjivosti programske biblioteke libwmf

Ranjivosti programske biblioteke libwmf

  • Detalji os-a: LDE
  • Važnost: IMP
  • Operativni sustavi: L
  • Kategorije: LDE

—–BEGIN PGP SIGNED MESSAGE—–
Hash: SHA1

– ————————————————————————-
Debian Security Advisory DSA-3302-1 security@debian.org
https://www.debian.org/security/ Moritz Muehlenhoff
July 06, 2015 https://www.debian.org/security/faq
– ————————————————————————-

Package : libwmf
CVE ID : CVE-2015-0848 CVE-2015-4588 CVE-2015-4695 CVE-2015-4696

Insufficient input sanitising in libwmf, a library to process Windows
metafile data, may result in denial of service or the execution of
arbitrary code if a malformed WMF file is opened.

For the oldstable distribution (wheezy), these problems have been fixed
in version 0.2.8.4-10.3+deb7u1.

For the stable distribution (jessie), these problems have been fixed in
version 0.2.8.4-10.3+deb8u1.

For the unstable distribution (sid), these problems will be fixed soon.

We recommend that you upgrade your libwmf packages.

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/

Mailing list: debian-security-announce@lists.debian.org
—–BEGIN PGP SIGNATURE—–
Version: GnuPG v1

iQIcBAEBAgAGBQJVmuviAAoJEBDCk7bDfE42fFEP/1zDnj23DcAk4rlmDzvdRwEC
hETr0DcvBMWw3nzBYQ7IYO7nH1vKJmsomLwsiu52EA6mUYJckdQ/4qr3mcE4Agm/
JwnvAY7TYeNKICrhiza+DEnQYk2CRmy1LdgrvhLv2QEyyRclc8WlimSB3T6dbiwC
wjWCrI3SA1ud7NT//aRRJ0NUc9Q1w/V84/coRt+yvzSV8dMuunj5SSzm8KA7qNm2
jQWPq6Kh0/LnlLPvyq8Nr5bEc8ng3Nh336sGuKs/BhObi2iSlgiqdehzD6VUG8Hu
wzcTdQ/AMofILoAm+sBw8Akxu80oanShdITfwpC7i22LzQdDJWRQFOJqPCIGbsLu
IF2y1SP93Bd4f9rk/yhzzjImdcUCPdJLflO1XVW5+qsRy1dUFHBe8aqCZHBsLVqm
Gd5yah68awXHH/PSWEO4cDtoiJq3iBfvKVqO3Ur1ceX9MuS3Z5udIz8Yrq8mmi9g
olO8tVsPKfYe5kwIRi5S71ustYLHmdJ9CUHl7tMQ6LrSXAUybSnZHy8bK77hcRe2
LL0Src4ioCljR8gTYKAxMtKt0s2dyjGVACh9ScGcQZIMH9JueZnXsj9hURAsu1Jn
kB3nWB1UxmOzsEjGZ/ud2yCBYO4I5oAW1QJmGj4FYH1rt3LtwYeMz5YnB3BuugVS
miSRB5gn5FyaIT+I3iTY
=hkJ/
—–END PGP SIGNATURE—–


To UNSUBSCRIBE, email to debian-security-announce-REQUEST@lists.debian.org
with a subject of “unsubscribe”. Trouble? Contact listmaster@lists.debian.org
Archive: https://lists.debian.org/20150706205853.GA27673@pisco.westfalen.local

AutorTomislav Protega
Cert idNCERT-REF-2015-07-0013-ADV
CveCVE-2015-0848 CVE-2015-4588 CVE-2015-4695 CVE-2015-4696
ID izvornikaDSA-3302-1
Proizvodlibwmf
Izvorhttp://www.debian.org
Top
More in Preporuke
Ranjivosti programskog paketa tor

Otkrivene su dvije ranjivosti u programskom paketu tor za Gentoo. Ranjivosti su posljedica progrešne provjere programskog koda (assertion failure) kod...

Close