GLSA Advocate
![Advocate Advocate](/images/ranks/rank-G-1-advocate.gif)
Joined: 12 May 2004 Posts: 2663
|
Posted: Sat Feb 27, 2016 2:26 am Post subject: [ GLSA 201602-03 ] libwmf |
|
|
Gentoo Linux Security Advisory
Title: libwmf: Multiple vulnerabilities (GLSA 201602-03)
Severity: normal
Exploitable: remote
Date: February 27, 2016
Bug(s): #551144, #553818
ID: 201602-03
Synopsis
Multiple vulnerabilities have been found in libwmf allowing remote
attackers to execute arbitrary code or cause Denial of Service.
Background
libwmf is a library for converting WMF files.
Affected Packages
Package: media-libs/libwmf
Vulnerable: < 0.2.8.4-r6
Unaffected: >= 0.2.8.4-r6
Architectures: All supported architectures
Description
Multiple vulnerabilities have been discovered in libwmf. Please review
the CVE identifiers referenced below for details.
Impact
A remote attacker could possibly execute arbitrary code with the
privileges of the process or cause Denial of Service.
Workaround
There is no known work around at this time.
Resolution
All libwmf users should upgrade to the latest version: Code: | # emerge --sync
# emerge --ask --oneshot --verbose ">=media-libs/libwmf-0.2.8.4-r6"
|
References
CVE-2015-0848
CVE-2015-4588
CVE-2015-4695
CVE-2015-4696
|
|