PT-2015-6673 · Sourceforge+5 · Libwmf+5

Fernando Muñoz

·

Published

2015-07-01

·

Updated

2025-09-03

·

CVE-2015-4696

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions libwmf version 0.2.8.4
Description The issue is related to a use-after-free vulnerability that can be triggered by remote attackers using a crafted WMF file. This can cause a denial of service, leading to a crash, specifically when the file is processed by the wmf2gd or wmf2eps command.
Recommendations For libwmf version 0.2.8.4, consider updating to a newer version that addresses this issue, as using a crafted WMF file can cause a denial of service. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Related Identifiers

ALT-PU-2017-2327
ALT-PU-2025-10401
ALT-PU-2025-11012
CESA-2015_1917
CVE-2015-4696
DLA-257-1
DSA-3302-1
MGASA-2015-0261
OPENSUSE-SU-2024:10337-1
RHSA-2015:1917
RHSA-2015_1917
SUSE-SU-2015:1378-1
SUSE-SU-2015:1484-1
USN-2670-1

Affected Products

Alt Linux
Centos
Red Hat
Suse
Ubuntu
Libwmf