CVE-2015-0848
published 2015-07-01CVE-2015-0848: Heap-based buffer overflow in libwmf 0.2.8.4 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted BMP…
PriorityP342medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
8.54%
94.4th percentile
Heap-based buffer overflow in libwmf 0.2.8.4 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted BMP image.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libwmf | < libwmf 0.2.8.4-10.4 (bookworm) | libwmf 0.2.8.4-10.4 (bookworm) |
| fedoraproject | fedora | — | — |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
| wvware | libwmf | — | — |
| wvware | libwmf | >= 0 < 0.2.8.4-10.4 | 0.2.8.4-10.4 |
| wvware | libwmf | >= 0 < 0.2.8.4-10.4 | 0.2.8.4-10.4 |
| wvware | libwmf | >= 0 < 0.2.8.4-10.4 | 0.2.8.4-10.4 |
| wvware | libwmf | >= 0 < 0.2.8.4-10.4 | 0.2.8.4-10.4 |
CVSS provenance
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv6.8MEDIUM
vendor_debian6.8MEDIUM
vendor_redhat6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-8h7p-8xq5-x3gj: Heap-based buffer overflow in libwmf 0
ghsa_unreviewed·2022-05-14
CVE-2015-0848 [MEDIUM] CWE-119 GHSA-8h7p-8xq5-x3gj: Heap-based buffer overflow in libwmf 0
Heap-based buffer overflow in libwmf 0.2.8.4 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted BMP image.
OSV
CVE-2015-0848: Heap-based buffer overflow in libwmf 0
osv·2015-07-01·CVSS 6.8
CVE-2015-0848 [MEDIUM] CVE-2015-0848: Heap-based buffer overflow in libwmf 0
Heap-based buffer overflow in libwmf 0.2.8.4 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted BMP image.
Ubuntu
libwmf vulnerabilities
vendor_ubuntu·2015-07-08
CVE-2015-4588 libwmf vulnerabilities
Title: libwmf vulnerabilities
Summary: libwmf could be made to crash or run programs as your login if it opened a
specially crafted file.
Fernando Muñoz and Stefan Cornelius discovered that libwmf incorrectly
handled certain malformed images. If a user or automated system were
tricked into opening a crafted image file, an attacker could cause a denial
of service or execute arbitrary code with privileges of the user invoking
the program.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
libwmf: heap overflow when decoding BMP images
vendor_redhat·2015-06-01·CVSS 6.8
CVE-2015-0848 [MEDIUM] CWE-122 libwmf: heap overflow when decoding BMP images
libwmf: heap overflow when decoding BMP images
Heap-based buffer overflow in libwmf 0.2.8.4 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted BMP image.
It was discovered that libwmf did not correctly process certain WMF (Windows Metafiles) containing BMP images. By tricking a victim into opening a specially crafted WMF file in an application using libwmf, a remote attacker could possibly use this flaw to execute arbitrary code with the privileges of the user running the application.
Package: libwmf (Red Hat Enterprise Linux 5) - Will not fix
Debian
CVE-2015-0848: libwmf - Heap-based buffer overflow in libwmf 0.2.8.4 allows remote attackers to cause a ...
vendor_debian·2015·CVSS 6.8
CVE-2015-0848 [MEDIUM] CVE-2015-0848: libwmf - Heap-based buffer overflow in libwmf 0.2.8.4 allows remote attackers to cause a ...
Heap-based buffer overflow in libwmf 0.2.8.4 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted BMP image.
Scope: local
bookworm: resolved (fixed in 0.2.8.4-10.4)
bullseye: resolved (fixed in 0.2.8.4-10.4)
forky: resolved (fixed in 0.2.8.4-10.4)
sid: resolved (fixed in 0.2.8.4-10.4)
trixie: resolved (fixed in 0.2.8.4-10.4)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-0848 libwmf: heap overflow when decoding BMP images [fedora-all]
bugzilla·2015-06-02·CVSS 6.8
CVE-2015-0848 [MEDIUM] CVE-2015-0848 libwmf: heap overflow when decoding BMP images [fedora-all]
CVE-2015-0848 libwmf: heap overflow when decoding BMP images [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedo
Bugzilla
CVE-2015-0848 libwmf: heap overflow when decoding BMP images
bugzilla·2015-06-02·CVSS 6.8
CVE-2015-0848 [MEDIUM] CVE-2015-0848 libwmf: heap overflow when decoding BMP images
CVE-2015-0848 libwmf: heap overflow when decoding BMP images
A heap buffer overflow flaw was found in the way the libwmf library processed WMF files containing BMP images. A specially crafted WMF file could cause an application using libwmf to crash or, possibly, execute arbitrary code.
Original report:
http://seclists.org/oss-sec/2015/q2/597
Discussion:
Created libwmf tracking bugs for this issue:
Affects: fedora-all [bug 1227244]
---
Created attachment 1033697
a fix
seeing as DecodeImage assumes that one pixel is one byte then it would appear that the most straight-forward fix is to only call DecodeImage if that is the case
---
I believe that there are further problems. The RLE decoding doesn't seem to check that the "count" fits into the image.
==4960== Invalid write of size
http://lists.fedoraproject.org/pipermail/package-announce/2015-June/160668.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-October/168507.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-September/165547.htmlhttp://lists.opensuse.org/opensuse-updates/2015-06/msg00051.htmlhttp://lists.opensuse.org/opensuse-updates/2015-06/msg00053.htmlhttp://lists.opensuse.org/opensuse-updates/2015-07/msg00018.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1917.htmlhttp://www.debian.org/security/2015/dsa-3302http://www.openwall.com/lists/oss-security/2015/06/01/2http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.htmlhttp://www.securityfocus.com/bid/74923http://www.securitytracker.com/id/1032771http://www.ubuntu.com/usn/USN-2670-1https://security.gentoo.org/glsa/201602-03http://lists.fedoraproject.org/pipermail/package-announce/2015-June/160668.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-October/168507.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-September/165547.htmlhttp://lists.opensuse.org/opensuse-updates/2015-06/msg00051.htmlhttp://lists.opensuse.org/opensuse-updates/2015-06/msg00053.htmlhttp://lists.opensuse.org/opensuse-updates/2015-07/msg00018.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1917.htmlhttp://www.debian.org/security/2015/dsa-3302http://www.openwall.com/lists/oss-security/2015/06/01/2http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.htmlhttp://www.securityfocus.com/bid/74923http://www.securitytracker.com/id/1032771http://www.ubuntu.com/usn/USN-2670-1https://security.gentoo.org/glsa/201602-03
2015-07-01
Published