CVE-2006-3376

Integer overflow in player.c in libwmf 0.2.8.4, as used in multiple products including (1) wv, (2) abiword, (3) freetype, (4) gimp, (5) libgsf, and (6) imagemagick allows remote attackers to execute arbitrary code via the MaxRecordSize header field in a WMF file.
References
Link Resource
http://rhn.redhat.com/errata/RHSA-2006-0597.html
http://secunia.com/advisories/20921 Vendor Advisory
http://secunia.com/advisories/21064
http://secunia.com/advisories/21261
http://secunia.com/advisories/21419
http://secunia.com/advisories/21459
http://secunia.com/advisories/21473
http://secunia.com/advisories/22311
http://security.gentoo.org/glsa/glsa-200608-17.xml
http://securityreason.com/securityalert/1190
http://securitytracker.com/id?1016518
http://www.mandriva.com/security/advisories?name=MDKSA-2006:132
http://www.novell.com/linux/security/advisories/2006_19_sr.html
http://www.securityfocus.com/archive/1/438803/100/0/threaded
http://www.securityfocus.com/bid/18751
http://www.ubuntu.com/usn/usn-333-1
http://www.vupen.com/english/advisories/2006/2646
https://exchange.xforce.ibmcloud.com/vulnerabilities/27516
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10262
https://www.debian.org/security/2006/dsa-1194
http://rhn.redhat.com/errata/RHSA-2006-0597.html
http://secunia.com/advisories/20921 Vendor Advisory
http://secunia.com/advisories/21064
http://secunia.com/advisories/21261
http://secunia.com/advisories/21419
http://secunia.com/advisories/21459
http://secunia.com/advisories/21473
http://secunia.com/advisories/22311
http://security.gentoo.org/glsa/glsa-200608-17.xml
http://securityreason.com/securityalert/1190
http://securitytracker.com/id?1016518
http://www.mandriva.com/security/advisories?name=MDKSA-2006:132
http://www.novell.com/linux/security/advisories/2006_19_sr.html
http://www.securityfocus.com/archive/1/438803/100/0/threaded
http://www.securityfocus.com/bid/18751
http://www.ubuntu.com/usn/usn-333-1
http://www.vupen.com/english/advisories/2006/2646
https://exchange.xforce.ibmcloud.com/vulnerabilities/27516
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10262
https://www.debian.org/security/2006/dsa-1194
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:wvware:libwmf:0.2.8_.4:*:*:*:*:*:*:*
cpe:2.3:a:wvware:wv2:0.2.1:*:*:*:*:*:*:*
cpe:2.3:a:wvware:wv2:0.2.2:*:*:*:*:*:*:*
cpe:2.3:a:wvware:wv2:0.2.3:*:*:*:*:*:*:*

History

21 Nov 2024, 00:13

Type Values Removed Values Added
References () http://rhn.redhat.com/errata/RHSA-2006-0597.html - () http://rhn.redhat.com/errata/RHSA-2006-0597.html -
References () http://secunia.com/advisories/20921 - Vendor Advisory () http://secunia.com/advisories/20921 - Vendor Advisory
References () http://secunia.com/advisories/21064 - () http://secunia.com/advisories/21064 -
References () http://secunia.com/advisories/21261 - () http://secunia.com/advisories/21261 -
References () http://secunia.com/advisories/21419 - () http://secunia.com/advisories/21419 -
References () http://secunia.com/advisories/21459 - () http://secunia.com/advisories/21459 -
References () http://secunia.com/advisories/21473 - () http://secunia.com/advisories/21473 -
References () http://secunia.com/advisories/22311 - () http://secunia.com/advisories/22311 -
References () http://security.gentoo.org/glsa/glsa-200608-17.xml - () http://security.gentoo.org/glsa/glsa-200608-17.xml -
References () http://securityreason.com/securityalert/1190 - () http://securityreason.com/securityalert/1190 -
References () http://securitytracker.com/id?1016518 - () http://securitytracker.com/id?1016518 -
References () http://www.mandriva.com/security/advisories?name=MDKSA-2006:132 - () http://www.mandriva.com/security/advisories?name=MDKSA-2006:132 -
References () http://www.novell.com/linux/security/advisories/2006_19_sr.html - () http://www.novell.com/linux/security/advisories/2006_19_sr.html -
References () http://www.securityfocus.com/archive/1/438803/100/0/threaded - () http://www.securityfocus.com/archive/1/438803/100/0/threaded -
References () http://www.securityfocus.com/bid/18751 - () http://www.securityfocus.com/bid/18751 -
References () http://www.ubuntu.com/usn/usn-333-1 - () http://www.ubuntu.com/usn/usn-333-1 -
References () http://www.vupen.com/english/advisories/2006/2646 - () http://www.vupen.com/english/advisories/2006/2646 -
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/27516 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/27516 -
References () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10262 - () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10262 -
References () https://www.debian.org/security/2006/dsa-1194 - () https://www.debian.org/security/2006/dsa-1194 -

Information

Published : 2006-07-06 20:05

Updated : 2024-11-21 00:13


NVD link : CVE-2006-3376

Mitre link : CVE-2006-3376

CVE.ORG link : CVE-2006-3376


JSON object : View

Products Affected

wvware

  • wv2
  • libwmf