PT-2006-4268 · Linux+2 · Imagemagick+8

·

CVE-2006-3376

·

Published

2006-07-06

·

Updated

2025-09-03

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions libwmf version 0.2.8.4
Description The issue is related to an integer overflow in the player.c file of libwmf, which can be exploited by remote attackers to execute arbitrary code. This is achieved through the MaxRecordSize header field in a WMF file. The affected products include wv, abiword, freetype, gimp, libgsf, and imagemagick.
Recommendations For libwmf version 0.2.8.4, update to a newer version that contains a fix for this issue.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

ALT-PU-2025-10401
ALT-PU-2025-11012
CVE-2006-3376
DSA-1194-1
OPENSUSE-SU-2024:11012-1
RHSA-2006:0597
RHSA-2006_0597

Affected Products

Alt Linux
Red Hat
Abiword
Freetype
Gimp
Imagemagick
Libgsf
Libwmf
Wv