First published: Thu Jul 06 2006(Updated: )
Integer overflow in player.c in libwmf 0.2.8.4, as used in multiple products including (1) wv, (2) abiword, (3) freetype, (4) gimp, (5) libgsf, and (6) imagemagick allows remote attackers to execute arbitrary code via the MaxRecordSize header field in a WMF file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
debian/libwmf | 0.2.8.4-14 0.2.8.4-17 0.2.12-5.1 0.2.13-1 | |
Wvware Wv2 | =0.2.3 | |
Wvware Wv2 | =0.2.1 | |
libwmf | =0.2.8_.4 | |
Wvware Wv2 | =0.2.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-3376 has a high severity rating due to the potential for remote code execution.
To fix CVE-2006-3376, upgrade to a patched version of libwmf, specifically any version later than 0.2.8.4-17.
CVE-2006-3376 affects multiple products including wv, abiword, freetype, gimp, libgsf, and imagemagick that use libwmf.
CVE-2006-3376 allows remote attackers to execute arbitrary code by exploiting the MaxRecordSize header field in a WMF file.
Yes, CVE-2006-3376 is considered a common vulnerability as it affects widely used software and libraries.