CentOS.Security.Update.for.Libwmf

NameCentOS.Security.Update.for.Libwmf.CESA-2006-0597
Release DateMay 25, 2010
SeverityMedium
ImpactThis vulnerability could cause execution of arbitrary code.
DescriptionLibwmf is a library for reading and converting Windows MetaFile vector graphics (WMF) used by packages such as GIMP and ImageMagick.

An integer overflow flaw was discovered in libwmf. An attacker could create a carefully crafted WMF flaw that could execute arbitrary code if opened by a victim. (CVE-2006-3376).
Recommended ActionsTo resolve this issue, please upgrade to the latest packages which contain a backported patch.
Refer to CentOS advisory CentOS 4 ia64 CentOS 4 axp CentOS 4 s390 CentOS 4 x86_64 CentOS 4 i386 for updates and patch information.
Common Vulnerabilities and Exposures (CVE)http://cve.mitre.org/cgi-bin/cvename.cgi?name=2006-3376
Reference: VID-23101