Logo
vulnerabilityCVE-2006-3376
Name
CVE-2006-3376
Source
NVD ( link)Debian ( link)
Description
Integer overflow in player.c in libwmf 0.2.8.4, as used in multiple products including (1) wv, (2) abiword, (3) freetype, (4) gimp, (5) libgsf, and (6) imagemagick allows remote attackers to execute arbitrary code via the MaxRecordSize header field in a WMF file.
CWEs
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
libwmf
Patched

Vulnerability Rating#


7.5
CVSSv2

Others affected components#


Name
Project
Project Version
Version
Status
yocto
master
0.2.13
Not Affected
yocto
scarthgap
0.2.8.4
Patched

Resolved with patches#


libwmf (yocto:kirkstone)

#
Title
Author
Resolve
1
Patch #1
Unknown
CVE-2006-3376

libwmf (yocto:scarthgap)

#
Title
Author
Resolve
1
Patch #1
Unknown
CVE-2006-3376