• [SECURITY] [DSA 3302-1] libwmf security update

    From Moritz Muehlenhoff@1:229/2 to All on Mon Jul 6 23:10:02 2015
    From: [email protected]

    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA1

    - ------------------------------------------------------------------------- Debian Security Advisory DSA-3302-1 [email protected] https://www.debian.org/security/ Moritz Muehlenhoff
    July 06, 2015 https://www.debian.org/security/faq
    - -------------------------------------------------------------------------

    Package : libwmf
    CVE ID : CVE-2015-0848 CVE-2015-4588 CVE-2015-4695 CVE-2015-4696

    Insufficient input sanitising in libwmf, a library to process Windows
    metafile data, may result in denial of service or the execution of
    arbitrary code if a malformed WMF file is opened.

    For the oldstable distribution (wheezy), these problems have been fixed
    in version 0.2.8.4-10.3+deb7u1.

    For the stable distribution (jessie), these problems have been fixed in
    version 0.2.8.4-10.3+deb8u1.

    For the unstable distribution (sid), these problems will be fixed soon.

    We recommend that you upgrade your libwmf packages.

    Further information about Debian Security Advisories, how to apply
    these updates to your system and frequently asked questions can be
    found at: https://www.debian.org/security/

    Mailing list: [email protected]
    -----BEGIN PGP SIGNATURE-----
    Version: GnuPG v1

    iQIcBAEBAgAGBQJVmuviAAoJEBDCk7bDfE42fFEP/1zDnj23DcAk4rlmDzvdRwEC hETr0DcvBMWw3nzBYQ7IYO7nH1vKJmsomLwsiu52EA6mUYJckdQ/4qr3mcE4Agm/ JwnvAY7TYeNKICrhiza+DEnQYk2CRmy1LdgrvhLv2QEyyRclc8WlimSB3T6dbiwC wjWCrI3SA1ud7NT//aRRJ0NUc9Q1w/V84/coRt+yvzSV8dMuunj5SSzm8KA7qNm2 jQWPq6Kh0/LnlLPvyq8Nr5bEc8ng3Nh336sGuKs/BhObi2iSlgiqdehzD6VUG8Hu wzcTdQ/AMofILoAm+sBw8Akxu80oanShdITfwpC7i22LzQdDJWRQFOJqPCIGbsLu IF2y1SP93Bd4f9rk/yhzzjImdcUCPdJLflO1XVW5+qsRy1dUFHBe8aqCZHBsLVqm Gd5yah68awXHH/PSWEO4cDtoiJq3iBfvKVqO3Ur1ceX9MuS3Z5udIz8Yrq8mmi9g olO8tVsPKfYe5kwIRi5S71ustYLHmdJ9CUHl7tMQ6LrSXAUybSnZHy8bK77hcRe2 LL0Src4ioCljR8gTYKAxMtKt0s2dyjGVACh9ScGcQZIMH9JueZnXsj9hURAsu1Jn kB3nWB1UxmOzsEjGZ/ud2yCBYO4I5oAW1QJmGj4FYH1rt3LtwYeMz5YnB3BuugVS miSRB5gn5FyaIT+I3iTY
    =hkJ/
    -----END PGP SIGNATURE-----


    --
    To UNSUBSCRIBE, email to [email protected]
    with a subject of "unsubscribe". Trouble? Contact [email protected] Archive: https://lists.debian.org/[email protected]

    --- SoupGate-Win32 v1.05
    * Origin: you cannot sedate... all the things you hate (1:229/2)