CVE-2015-4695
published 2015-07-01CVE-2015-4695: meta.h in libwmf 0.2.8.4 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted WMF file.
PriorityP427medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
6.64%
93.1th percentile
meta.h in libwmf 0.2.8.4 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted WMF file.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libwmf | < libwmf 0.2.8.4-10.4 (bookworm) | libwmf 0.2.8.4-10.4 (bookworm) |
| wvware | libwmf | — | — |
| wvware | libwmf | >= 0 < 0.2.8.4-10.4 | 0.2.8.4-10.4 |
| wvware | libwmf | >= 0 < 0.2.8.4-10.4 | 0.2.8.4-10.4 |
| wvware | libwmf | >= 0 < 0.2.8.4-10.4 | 0.2.8.4-10.4 |
| wvware | libwmf | >= 0 < 0.2.8.4-10.4 | 0.2.8.4-10.4 |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv5.0MEDIUM
vendor_debian5.0MEDIUM
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-rrgp-f769-h4h5: meta
ghsa_unreviewed·2022-05-17
CVE-2015-4695 [MEDIUM] CWE-119 GHSA-rrgp-f769-h4h5: meta
meta.h in libwmf 0.2.8.4 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted WMF file.
OSV
CVE-2015-4695: meta
osv·2015-07-01·CVSS 5.0
CVE-2015-4695 [MEDIUM] CVE-2015-4695: meta
meta.h in libwmf 0.2.8.4 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted WMF file.
Ubuntu
libwmf vulnerabilities
vendor_ubuntu·2015-07-08
CVE-2015-4588 libwmf vulnerabilities
Title: libwmf vulnerabilities
Summary: libwmf could be made to crash or run programs as your login if it opened a
specially crafted file.
Fernando Muñoz and Stefan Cornelius discovered that libwmf incorrectly
handled certain malformed images. If a user or automated system were
tricked into opening a crafted image file, an attacker could cause a denial
of service or execute arbitrary code with privileges of the user invoking
the program.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
libwmf: heap buffer overread in meta.h
vendor_redhat·2015-05-04·CVSS 5.0
CVE-2015-4695 [MEDIUM] CWE-122 libwmf: heap buffer overread in meta.h
libwmf: heap buffer overread in meta.h
meta.h in libwmf 0.2.8.4 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted WMF file.
It was discovered that libwmf did not properly process certain WMF files. By tricking a victim into opening a specially crafted WMF file in an application using libwmf, a remote attacker could possibly exploit this flaw to cause a crash or execute arbitrary code with the privileges of the user running the application.
Package: libwmf (Red Hat Enterprise Linux 5) - Will not fix
Debian
CVE-2015-4695: libwmf - meta.h in libwmf 0.2.8.4 allows remote attackers to cause a denial of service (o...
vendor_debian·2015·CVSS 5.0
CVE-2015-4695 [MEDIUM] CVE-2015-4695: libwmf - meta.h in libwmf 0.2.8.4 allows remote attackers to cause a denial of service (o...
meta.h in libwmf 0.2.8.4 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted WMF file.
Scope: local
bookworm: resolved (fixed in 0.2.8.4-10.4)
bullseye: resolved (fixed in 0.2.8.4-10.4)
forky: resolved (fixed in 0.2.8.4-10.4)
sid: resolved (fixed in 0.2.8.4-10.4)
trixie: resolved (fixed in 0.2.8.4-10.4)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-4696 CVE-2015-4695 libwmf: various flaws [fedora-all]
bugzilla·2015-06-25·CVSS 5.0
CVE-2015-4696 [MEDIUM] CVE-2015-4696 CVE-2015-4695 libwmf: various flaws [fedora-all]
CVE-2015-4696 CVE-2015-4695 libwmf: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedora. While o
Bugzilla
CVE-2015-4695 libwmf: heap buffer overread in meta.h
bugzilla·2015-06-25·CVSS 5.0
CVE-2015-4695 [MEDIUM] CVE-2015-4695 libwmf: heap buffer overread in meta.h
CVE-2015-4695 libwmf: heap buffer overread in meta.h
A read from invalid address was reported in libwmf in couple of places in meta.h file
Originally reported in https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=784205
Patch is attached to BZ 1227243: https://bugzilla.redhat.com/attachment.cgi?id=1042306
Discussion:
Created libwmf tracking bugs for this issue:
Affects: fedora-all [bug 1235671]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Red Hat Enterprise Linux 6
Via RHSA-2015:1917 https://rhn.redhat.com/errata/RHSA-2015-1917.html
http://lists.fedoraproject.org/pipermail/package-announce/2015-July/162569.htmlhttp://lists.opensuse.org/opensuse-updates/2015-07/msg00018.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1917.htmlhttp://www.debian.org/security/2015/dsa-3302http://www.openwall.com/lists/oss-security/2015/06/17/3http://www.openwall.com/lists/oss-security/2015/06/21/3http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.htmlhttp://www.securityfocus.com/bid/75329http://www.securitytracker.com/id/1032771http://www.ubuntu.com/usn/USN-2670-1https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=784205https://security.gentoo.org/glsa/201602-03http://lists.fedoraproject.org/pipermail/package-announce/2015-July/162569.htmlhttp://lists.opensuse.org/opensuse-updates/2015-07/msg00018.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1917.htmlhttp://www.debian.org/security/2015/dsa-3302http://www.openwall.com/lists/oss-security/2015/06/17/3http://www.openwall.com/lists/oss-security/2015/06/21/3http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.htmlhttp://www.securityfocus.com/bid/75329http://www.securitytracker.com/id/1032771http://www.ubuntu.com/usn/USN-2670-1https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=784205https://security.gentoo.org/glsa/201602-03
2015-07-01
Published