This application requires Javascript for optimal performance.

CentOS.Security.Update.for.Libwmf.CESA-2006-0597

Release Date

May 25, 2010

Severity

medium

Impact

This vulnerability could cause execution of arbitrary code.

Description

Libwmf is a library for reading and converting Windows MetaFile vector graphics (WMF) used by packages such as GIMP and ImageMagick.

An integer overflow flaw was discovered in libwmf. An attacker could create a carefully crafted WMF flaw that could execute arbitrary code if opened by a victim. (CVE-2006-3376).

Affected Products

Recommended Actions

To resolve this issue, please upgrade to the latest packages which contain a backported patch.
Refer to CentOS advisory CESA-2006:0597, containing updates and patches information, for CentOS 4 ia64, CentOS 4 axp, CentOS 4 s390, CentOS 4 x86_64 and CentOS 4 i386.

Coverage

IPS
VCM

Common Vulnerabilities and Exposures (CVE)

CVE-2006-3376

Reference: VID-23101