Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.880898
Category:CentOS Local Security Checks
Title:CentOS Update for libwmf CESA-2009:0457 centos4 i386
Summary:The remote host is missing an update for the 'libwmf'; package(s) announced via the referenced advisory.
Description:Summary:
The remote host is missing an update for the 'libwmf'
package(s) announced via the referenced advisory.

Vulnerability Insight:
libwmf is a library for reading and converting Windows Metafile Format
(WMF) vector graphics. libwmf is used by applications such as GIMP and
ImageMagick.

A pointer use-after-free flaw was found in the GD graphics library embedded
in libwmf. An attacker could create a specially-crafted WMF file that would
cause an application using libwmf to crash or, potentially, execute
arbitrary code as the user running the application when opened by a victim.
(CVE-2009-1364)

Note: This flaw is specific to the GD graphics library embedded in libwmf.
It does not affect the GD graphics library from the 'gd' packages, or
applications using it.

Red Hat would like to thank Tavis Ormandy of the Google Security Team for
responsibly reporting this flaw.

All users of libwmf are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue. After installing the
update, all applications using libwmf must be restarted for the update
to take effect.

Affected Software/OS:
libwmf on CentOS 4

Solution:
Please install the updated packages.

CVSS Score:
7.5

CVSS Vector:
AV:N/AC:L/Au:N/C:P/I:P/A:P

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2009-1364
BugTraq ID: 34792
http://www.securityfocus.com/bid/34792
Debian Security Information: DSA-1796 (Google Search)
http://www.debian.org/security/2009/dsa-1796
https://www.redhat.com/archives/fedora-package-announce/2009-May/msg01269.html
https://www.redhat.com/archives/fedora-package-announce/2009-May/msg01263.html
https://www.redhat.com/archives/fedora-package-announce/2009-May/msg01266.html
http://security.gentoo.org/glsa/glsa-200907-01.xml
http://www.mandriva.com/security/advisories?name=MDVSA-2009:106
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10959
RedHat Security Advisories: RHSA-2009:0457
http://rhn.redhat.com/errata/RHSA-2009-0457.html
http://www.securitytracker.com/id?1022154
http://secunia.com/advisories/34901
http://secunia.com/advisories/34964
http://secunia.com/advisories/35001
http://secunia.com/advisories/35025
http://secunia.com/advisories/35190
http://secunia.com/advisories/35416
http://secunia.com/advisories/35686
SuSE Security Announcement: SUSE-SR:2009:011 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2009-06/msg00003.html
SuSE Security Announcement: openSUSE-SU-2015:1132 (Google Search)
http://lists.opensuse.org/opensuse-updates/2015-06/msg00051.html
SuSE Security Announcement: openSUSE-SU-2015:1134 (Google Search)
http://lists.opensuse.org/opensuse-updates/2015-06/msg00053.html
http://www.ubuntu.com/usn/USN-769-1
http://www.vupen.com/english/advisories/2009/1228
XForce ISS Database: libwmf-gdlibrary-code-execution(50290)
https://exchange.xforce.ibmcloud.com/vulnerabilities/50290
CopyrightCopyright (C) 2011 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.