CVE Vulnerabilities

CVE-2006-3376

Published: Jul 06, 2006 | Modified: Nov 21, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
UNTRIAGED

Integer overflow in player.c in libwmf 0.2.8.4, as used in multiple products including (1) wv, (2) abiword, (3) freetype, (4) gimp, (5) libgsf, and (6) imagemagick allows remote attackers to execute arbitrary code via the MaxRecordSize header field in a WMF file.

Affected Software

Name Vendor Start Version End Version
Libwmf Wvware 0.2.8_.4 (including) 0.2.8_.4 (including)
Wv2 Wvware 0.2.1 (including) 0.2.1 (including)
Wv2 Wvware 0.2.2 (including) 0.2.2 (including)
Wv2 Wvware 0.2.3 (including) 0.2.3 (including)
Red Hat Enterprise Linux 4 RedHat libwmf-0:0.2.8.3-5.3 *
Libwmf Ubuntu dapper *
Libwmf Ubuntu devel *
Libwmf Ubuntu edgy *
Libwmf Ubuntu feisty *

References