First published: Mon May 04 2015(Updated: )
meta.h in libwmf 0.2.8.4 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted WMF file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
debian/libwmf | 0.2.8.4-17 0.2.12-5.1 0.2.13-1.1 | |
libwmf | =0.2.8.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-4695 has been classified as a high severity vulnerability due to its potential to cause denial of service through out-of-bounds read.
To fix CVE-2015-4695, upgrade to a version of libwmf that is higher than 0.2.8.4, such as 0.2.12 or later.
CVE-2015-4695 can be exploited by remote attackers to trigger a denial of service condition through specially crafted WMF files.
Versions 0.2.8.4 and below of libwmf are affected by CVE-2015-4695.
Yes, CVE-2015-4695 can be weaponized easily by creating malicious WMF files to exploit the out-of-bounds read vulnerability.