[SECURITY] [DSA 3302-1] libwmf security update

From: Moritz Muehlenhoff <jmm@debian.org>
To: bugtraq@securityfocus.com
Cc:
Subject: [SECURITY] [DSA 3302-1] libwmf security update
Date:


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

- -------------------------------------------------------------------------
Debian Security Advisory DSA-3302-1                   security@debian.org
https://www.debian.org/security/                       Moritz Muehlenhoff
July 06, 2015                         https://www.debian.org/security/faq
- -------------------------------------------------------------------------

Package        : libwmf
CVE ID         : CVE-2015-0848 CVE-2015-4588 CVE-2015-4695 CVE-2015-4696

Insufficient input sanitising in libwmf, a library to process Windows
metafile data, may result in denial of service or the execution of
arbitrary code if a malformed WMF file is opened.

For the oldstable distribution (wheezy), these problems have been fixed
in version 0.2.8.4-10.3+deb7u1.

For the stable distribution (jessie), these problems have been fixed in
version 0.2.8.4-10.3+deb8u1.

For the unstable distribution (sid), these problems will be fixed soon.

We recommend that you upgrade your libwmf packages.

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/

Mailing list: debian-security-announce@lists.debian.org
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1

iQIcBAEBAgAGBQJVmuviAAoJEBDCk7bDfE42fFEP/1zDnj23DcAk4rlmDzvdRwEC
hETr0DcvBMWw3nzBYQ7IYO7nH1vKJmsomLwsiu52EA6mUYJckdQ/4qr3mcE4Agm/
JwnvAY7TYeNKICrhiza+DEnQYk2CRmy1LdgrvhLv2QEyyRclc8WlimSB3T6dbiwC
wjWCrI3SA1ud7NT//aRRJ0NUc9Q1w/V84/coRt+yvzSV8dMuunj5SSzm8KA7qNm2
jQWPq6Kh0/LnlLPvyq8Nr5bEc8ng3Nh336sGuKs/BhObi2iSlgiqdehzD6VUG8Hu
wzcTdQ/AMofILoAm+sBw8Akxu80oanShdITfwpC7i22LzQdDJWRQFOJqPCIGbsLu
IF2y1SP93Bd4f9rk/yhzzjImdcUCPdJLflO1XVW5+qsRy1dUFHBe8aqCZHBsLVqm
Gd5yah68awXHH/PSWEO4cDtoiJq3iBfvKVqO3Ur1ceX9MuS3Z5udIz8Yrq8mmi9g
olO8tVsPKfYe5kwIRi5S71ustYLHmdJ9CUHl7tMQ6LrSXAUybSnZHy8bK77hcRe2
LL0Src4ioCljR8gTYKAxMtKt0s2dyjGVACh9ScGcQZIMH9JueZnXsj9hURAsu1Jn
kB3nWB1UxmOzsEjGZ/ud2yCBYO4I5oAW1QJmGj4FYH1rt3LtwYeMz5YnB3BuugVS
miSRB5gn5FyaIT+I3iTY
=hkJ/
-----END PGP SIGNATURE-----





Copyright © 1995-2018 LinuxRocket.net. All rights reserved.