CVE-2015-4696
published 2015-07-01CVE-2015-4696: Use-after-free vulnerability in libwmf 0.2.8.4 allows remote attackers to cause a denial of service (crash) via a crafted WMF file to the (1) wmf2gd or (2)…
PriorityP422medium4.3CVSS 2.0
AVNACMAuNCNINAP
EPSS
5.98%
92.5th percentile
Use-after-free vulnerability in libwmf 0.2.8.4 allows remote attackers to cause a denial of service (crash) via a crafted WMF file to the (1) wmf2gd or (2) wmf2eps command.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libwmf | < libwmf 0.2.8.4-10.4 (bookworm) | libwmf 0.2.8.4-10.4 (bookworm) |
| wvware | libwmf | — | — |
| wvware | libwmf | >= 0 < 0.2.8.4-10.4 | 0.2.8.4-10.4 |
| wvware | libwmf | >= 0 < 0.2.8.4-10.4 | 0.2.8.4-10.4 |
| wvware | libwmf | >= 0 < 0.2.8.4-10.4 | 0.2.8.4-10.4 |
| wvware | libwmf | >= 0 < 0.2.8.4-10.4 | 0.2.8.4-10.4 |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv4.3MEDIUM
vendor_debian4.3MEDIUM
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
libwmf vulnerabilities
vendor_ubuntu·2015-07-08
CVE-2015-4588 libwmf vulnerabilities
Title: libwmf vulnerabilities
Summary: libwmf could be made to crash or run programs as your login if it opened a
specially crafted file.
Fernando Muñoz and Stefan Cornelius discovered that libwmf incorrectly
handled certain malformed images. If a user or automated system were
tricked into opening a crafted image file, an attacker could cause a denial
of service or execute arbitrary code with privileges of the user invoking
the program.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
libwmf: use-after-free flaw in meta.h
vendor_redhat·2015-05-03·CVSS 4.3
CVE-2015-4696 [MEDIUM] CWE-416 libwmf: use-after-free flaw in meta.h
libwmf: use-after-free flaw in meta.h
Use-after-free vulnerability in libwmf 0.2.8.4 allows remote attackers to cause a denial of service (crash) via a crafted WMF file to the (1) wmf2gd or (2) wmf2eps command.
It was discovered that libwmf did not properly process certain WMF files. By tricking a victim into opening a specially crafted WMF file in an application using libwmf, a remote attacker could possibly exploit this flaw to cause a crash or execute arbitrary code with the privileges of the user running the application.
Package: libwmf (Red Hat Enterprise Linux 5) - Will not fix
Debian
CVE-2015-4696: libwmf - Use-after-free vulnerability in libwmf 0.2.8.4 allows remote attackers to cause ...
vendor_debian·2015·CVSS 4.3
CVE-2015-4696 [MEDIUM] CVE-2015-4696: libwmf - Use-after-free vulnerability in libwmf 0.2.8.4 allows remote attackers to cause ...
Use-after-free vulnerability in libwmf 0.2.8.4 allows remote attackers to cause a denial of service (crash) via a crafted WMF file to the (1) wmf2gd or (2) wmf2eps command.
Scope: local
bookworm: resolved (fixed in 0.2.8.4-10.4)
bullseye: resolved (fixed in 0.2.8.4-10.4)
forky: resolved (fixed in 0.2.8.4-10.4)
sid: resolved (fixed in 0.2.8.4-10.4)
trixie: resolved (fixed in 0.2.8.4-10.4)
GHSA
GHSA-4c7m-gh7v-c837: Use-after-free vulnerability in libwmf 0
ghsa_unreviewed·2022-05-17
CVE-2015-4696 [MEDIUM] GHSA-4c7m-gh7v-c837: Use-after-free vulnerability in libwmf 0
Use-after-free vulnerability in libwmf 0.2.8.4 allows remote attackers to cause a denial of service (crash) via a crafted WMF file to the (1) wmf2gd or (2) wmf2eps command.
OSV
CVE-2015-4696: Use-after-free vulnerability in libwmf 0
osv·2015-07-01·CVSS 4.3
CVE-2015-4696 [MEDIUM] CVE-2015-4696: Use-after-free vulnerability in libwmf 0
Use-after-free vulnerability in libwmf 0.2.8.4 allows remote attackers to cause a denial of service (crash) via a crafted WMF file to the (1) wmf2gd or (2) wmf2eps command.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-4696 libwmf: use-after-free flaw in meta.h
bugzilla·2015-06-25·CVSS 4.3
CVE-2015-4696 [MEDIUM] CVE-2015-4696 libwmf: use-after-free flaw in meta.h
CVE-2015-4696 libwmf: use-after-free flaw in meta.h
Use after free issue was reported in libwmf when processing a crafted WMF file.
Originally reported in https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=784192
Patch is attached in BZ 1227243: https://bugzilla.redhat.com/attachment.cgi?id=1042307
Discussion:
Created libwmf tracking bugs for this issue:
Affects: fedora-all [bug 1235671]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Red Hat Enterprise Linux 6
Via RHSA-2015:1917 https://rhn.redhat.com/errata/RHSA-2015-1917.html
Bugzilla
CVE-2015-4696 CVE-2015-4695 libwmf: various flaws [fedora-all]
bugzilla·2015-06-25·CVSS 5.0
CVE-2015-4696 [MEDIUM] CVE-2015-4696 CVE-2015-4695 libwmf: various flaws [fedora-all]
CVE-2015-4696 CVE-2015-4695 libwmf: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedora. While o
Bugzilla
CVE-2015-0848 libwmf: heap overflow when decoding BMP images
bugzilla·2015-06-02·CVSS 6.8
CVE-2015-0848 [MEDIUM] CVE-2015-0848 libwmf: heap overflow when decoding BMP images
CVE-2015-0848 libwmf: heap overflow when decoding BMP images
A heap buffer overflow flaw was found in the way the libwmf library processed WMF files containing BMP images. A specially crafted WMF file could cause an application using libwmf to crash or, possibly, execute arbitrary code.
Original report:
http://seclists.org/oss-sec/2015/q2/597
Discussion:
Created libwmf tracking bugs for this issue:
Affects: fedora-all [bug 1227244]
---
Created attachment 1033697
a fix
seeing as DecodeImage assumes that one pixel is one byte then it would appear that the most straight-forward fix is to only call DecodeImage if that is the case
---
I believe that there are further problems. The RLE decoding doesn't seem to check that the "count" fits into the image.
==4960== Invalid write of size
http://lists.fedoraproject.org/pipermail/package-announce/2015-July/162569.htmlhttp://lists.opensuse.org/opensuse-updates/2015-07/msg00018.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1917.htmlhttp://www.debian.org/security/2015/dsa-3302http://www.openwall.com/lists/oss-security/2015/06/17/3http://www.openwall.com/lists/oss-security/2015/06/21/3http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.htmlhttp://www.securityfocus.com/bid/75331http://www.securitytracker.com/id/1032771http://www.ubuntu.com/usn/USN-2670-1https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=784192https://security.gentoo.org/glsa/201602-03http://lists.fedoraproject.org/pipermail/package-announce/2015-July/162569.htmlhttp://lists.opensuse.org/opensuse-updates/2015-07/msg00018.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1917.htmlhttp://www.debian.org/security/2015/dsa-3302http://www.openwall.com/lists/oss-security/2015/06/17/3http://www.openwall.com/lists/oss-security/2015/06/21/3http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.htmlhttp://www.securityfocus.com/bid/75331http://www.securitytracker.com/id/1032771http://www.ubuntu.com/usn/USN-2670-1https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=784192https://security.gentoo.org/glsa/201602-03
2015-07-01
Published