CVE-2015-4588
published 2015-07-01CVE-2015-4588: Heap-based buffer overflow in the DecodeImage function in libwmf 0.2.8.4 allows remote attackers to cause a denial of service (crash) or possibly execute…
PriorityP341medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
9.22%
94.8th percentile
Heap-based buffer overflow in the DecodeImage function in libwmf 0.2.8.4 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted "run-length count" in an image in a WMF file.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libwmf | < libwmf 0.2.8.4-10.4 (bookworm) | libwmf 0.2.8.4-10.4 (bookworm) |
| fedoraproject | fedora | — | — |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
| wvware | libwmf | — | — |
| wvware | libwmf | >= 0 < 0.2.8.4-10.4 | 0.2.8.4-10.4 |
| wvware | libwmf | >= 0 < 0.2.8.4-10.4 | 0.2.8.4-10.4 |
| wvware | libwmf | >= 0 < 0.2.8.4-10.4 | 0.2.8.4-10.4 |
| wvware | libwmf | >= 0 < 0.2.8.4-10.4 | 0.2.8.4-10.4 |
CVSS provenance
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv6.8MEDIUM
vendor_debian6.8MEDIUM
vendor_redhat6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
libwmf vulnerabilities
vendor_ubuntu·2015-07-08
CVE-2015-4588 libwmf vulnerabilities
Title: libwmf vulnerabilities
Summary: libwmf could be made to crash or run programs as your login if it opened a
specially crafted file.
Fernando Muñoz and Stefan Cornelius discovered that libwmf incorrectly
handled certain malformed images. If a user or automated system were
tricked into opening a crafted image file, an attacker could cause a denial
of service or execute arbitrary code with privileges of the user invoking
the program.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
libwmf: heap overflow within the RLE decoding of embedded BMP images
vendor_redhat·2015-06-01·CVSS 6.8
CVE-2015-4588 [MEDIUM] CWE-122 libwmf: heap overflow within the RLE decoding of embedded BMP images
libwmf: heap overflow within the RLE decoding of embedded BMP images
Heap-based buffer overflow in the DecodeImage function in libwmf 0.2.8.4 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted "run-length count" in an image in a WMF file.
It was discovered that libwmf did not correctly process certain WMF (Windows Metafiles) with embedded BMP images. By tricking a victim into opening a specially crafted WMF file in an application using libwmf, a remote attacker could possibly use this flaw to execute arbitrary code with the privileges of the user running the application.
Package: libwmf (Red Hat Enterprise Linux 5) - Will not fix
Debian
CVE-2015-4588: libwmf - Heap-based buffer overflow in the DecodeImage function in libwmf 0.2.8.4 allows ...
vendor_debian·2015·CVSS 6.8
CVE-2015-4588 [MEDIUM] CVE-2015-4588: libwmf - Heap-based buffer overflow in the DecodeImage function in libwmf 0.2.8.4 allows ...
Heap-based buffer overflow in the DecodeImage function in libwmf 0.2.8.4 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted "run-length count" in an image in a WMF file.
Scope: local
bookworm: resolved (fixed in 0.2.8.4-10.4)
bullseye: resolved (fixed in 0.2.8.4-10.4)
forky: resolved (fixed in 0.2.8.4-10.4)
sid: resolved (fixed in 0.2.8.4-10.4)
trixie: resolved (fixed in 0.2.8.4-10.4)
GHSA
GHSA-v3qj-6mjm-fxx7: Heap-based buffer overflow in the DecodeImage function in libwmf 0
ghsa_unreviewed·2022-05-14
CVE-2015-4588 [MEDIUM] CWE-119 GHSA-v3qj-6mjm-fxx7: Heap-based buffer overflow in the DecodeImage function in libwmf 0
Heap-based buffer overflow in the DecodeImage function in libwmf 0.2.8.4 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted "run-length count" in an image in a WMF file.
OSV
CVE-2015-4588: Heap-based buffer overflow in the DecodeImage function in libwmf 0
osv·2015-07-01·CVSS 6.8
CVE-2015-4588 [MEDIUM] CVE-2015-4588: Heap-based buffer overflow in the DecodeImage function in libwmf 0
Heap-based buffer overflow in the DecodeImage function in libwmf 0.2.8.4 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted "run-length count" in an image in a WMF file.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-4588 libwmf: heap overflow within the RLE decoding of embedded BMP images
bugzilla·2015-10-19·CVSS 6.8
CVE-2015-4588 [MEDIUM] CVE-2015-4588 libwmf: heap overflow within the RLE decoding of embedded BMP images
CVE-2015-4588 libwmf: heap overflow within the RLE decoding of embedded BMP images
It was discovered that libwmf did not correctly process certain WMF (Windows Metafiles) with embedded RLE-compressed BMP images. By tricking a victim into opening a specially crafted WMF file in an application using libwmf, a remote attacker could possibly use this flaw to execute arbitrary code with the privileges of the user running the application.
Previously, this issue was bundled in bug#1227243.
Discussion:
The patch for this issue can be found in bug 1227243, comment 7.
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Red Hat Enterprise Linux 6
Via RHSA-2015:1917 https://rhn.redhat.com/errata/RHSA-2015-1917.html
Bugzilla
CVE-2015-0848 libwmf: heap overflow when decoding BMP images
bugzilla·2015-06-02·CVSS 6.8
CVE-2015-0848 [MEDIUM] CVE-2015-0848 libwmf: heap overflow when decoding BMP images
CVE-2015-0848 libwmf: heap overflow when decoding BMP images
A heap buffer overflow flaw was found in the way the libwmf library processed WMF files containing BMP images. A specially crafted WMF file could cause an application using libwmf to crash or, possibly, execute arbitrary code.
Original report:
http://seclists.org/oss-sec/2015/q2/597
Discussion:
Created libwmf tracking bugs for this issue:
Affects: fedora-all [bug 1227244]
---
Created attachment 1033697
a fix
seeing as DecodeImage assumes that one pixel is one byte then it would appear that the most straight-forward fix is to only call DecodeImage if that is the case
---
I believe that there are further problems. The RLE decoding doesn't seem to check that the "count" fits into the image.
==4960== Invalid write of size
http://lists.fedoraproject.org/pipermail/package-announce/2015-June/160668.htmlhttp://lists.opensuse.org/opensuse-updates/2015-06/msg00051.htmlhttp://lists.opensuse.org/opensuse-updates/2015-06/msg00053.htmlhttp://lists.opensuse.org/opensuse-updates/2015-07/msg00018.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1917.htmlhttp://www.debian.org/security/2015/dsa-3302http://www.openwall.com/lists/oss-security/2015/06/03/6http://www.openwall.com/lists/oss-security/2015/06/16/4http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.htmlhttp://www.securityfocus.com/bid/75230http://www.securitytracker.com/id/1032771http://www.ubuntu.com/usn/USN-2670-1https://bugzilla.redhat.com/show_bug.cgi?id=1227243https://security.gentoo.org/glsa/201602-03http://lists.fedoraproject.org/pipermail/package-announce/2015-June/160668.htmlhttp://lists.opensuse.org/opensuse-updates/2015-06/msg00051.htmlhttp://lists.opensuse.org/opensuse-updates/2015-06/msg00053.htmlhttp://lists.opensuse.org/opensuse-updates/2015-07/msg00018.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1917.htmlhttp://www.debian.org/security/2015/dsa-3302http://www.openwall.com/lists/oss-security/2015/06/03/6http://www.openwall.com/lists/oss-security/2015/06/16/4http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.htmlhttp://www.securityfocus.com/bid/75230http://www.securitytracker.com/id/1032771http://www.ubuntu.com/usn/USN-2670-1https://bugzilla.redhat.com/show_bug.cgi?id=1227243https://security.gentoo.org/glsa/201602-03
2015-07-01
Published