DSA-1796-1 libwmf -- pointer use-after-freeID: oval:org.secpod.oval:def:600415 | Date: (C)2011-05-13 (M)2022-10-10 |
Class: PATCH | Family: unix |
Tavis Ormandy discovered that the embedded GD library copy in libwmf, a library to parse windows metafiles , makes use of a pointer after it was already freed. An attacker using a crafted WMF file can cause a denial of service or possibly the execute arbitrary code via applications using this library. For the oldstable distribution , this problem has been fixed in version 0.2.8.4-2+etch1. For the stable distribution , this problem has been fixed in version 0.2.8.4-6+lenny1. For the testing distribution , this problem will be fixed soon. For the unstable distribution , this problem has been fixed in version 0.2.8.4-6.1. We recommend that you upgrade your libwmf packages.
Platform: |
Debian 5.0 |
Debian 4.0 |