DSA-1796-1 libwmf -- pointer use-after-free
|ID: oval:org.secpod.oval:def:600415||Date: (C)2011-05-13 (M)2018-03-27|
|Class: PATCH||Family: unix|
Tavis Ormandy discovered that the embedded GD library copy in libwmf, a library to parse windows metafiles , makes use of a pointer after it was already freed. An attacker using a crafted WMF file can cause a denial of service or possibly the execute arbitrary code via applications using this library. For the oldstable distribution , this problem has been fixed in version 0.2.8.4-2+etch1. For the stable distribution , this problem has been fixed in version 0.2.8.4-6+lenny1. For the testing distribution , this problem will be fixed soon. For the unstable distribution , this problem has been fixed in version 0.2.8.4-6.1. We recommend that you upgrade your libwmf packages.