FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2006-3376

This CVE name corresponds to:

Entered Topic
2009-05-16 libwmf -- integer overflow vulnerability

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2006-3376
Phase Assigned(20060706)

Description

Integer overflow in player.c in libwmf 0.2.8.4, as used in multiple products including (1) wv, (2) abiword, (3) freetype, (4) gimp, (5) libgsf, and (6) imagemagick allows remote attackers to execute arbitrary code via the MaxRecordSize header field in a WMF file.

References

Source Reference
BUGTRAQ 20060630 libwmf integer/heap overflow
DEBIAN DSA-1194
GENTOO GLSA-200608-17
MANDRIVA MDKSA-2006:132
REDHAT RHSA-2006:0597
SUSE SUSE-SR:2006:019
UBUNTU USN-333-1
BID 18751
OVAL oval:org.mitre.oval:def:10262
VUPEN ADV-2006-2646
SECTRACK 1016518
SECUNIA 20921
SECUNIA 21064
SECUNIA 21261
SECUNIA 21473
SECUNIA 21419
SECUNIA 22311
SECUNIA 21459
SREASON 1190
XF libwmf-wmf-bo(27516)