Oval Definition:oval:com.redhat.rhsa:def:20151917
Revision Date:2015-10-20Version:646
Title:RHSA-2015:1917: libwmf security update (Important)
Description:libwmf is a library for reading and converting Windows Metafile Format (WMF) vector graphics. libwmf is used by applications such as GIMP and ImageMagick.

  • It was discovered that libwmf did not correctly process certain WMF (Windows Metafiles) with embedded BMP images. By tricking a victim into opening a specially crafted WMF file in an application using libwmf, a remote attacker could possibly use this flaw to execute arbitrary code with the privileges of the user running the application. (CVE-2015-0848, CVE-2015-4588)

  • It was discovered that libwmf did not properly process certain WMF files. By tricking a victim into opening a specially crafted WMF file in an application using libwmf, a remote attacker could possibly exploit this flaw to cause a crash or execute arbitrary code with the privileges of the user running the application. (CVE-2015-4696)

  • It was discovered that libwmf did not properly process certain WMF files. By tricking a victim into opening a specially crafted WMF file in an application using libwmf, a remote attacker could possibly exploit this flaw to cause a crash. (CVE-2015-4695)

    All users of libwmf are advised to upgrade to these updated packages, which contain backported patches to correct these issues. After installing the update, all applications using libwmf must be restarted for the update to take effect.
  • Family:unixClass:patch
    Status:Reference(s):CVE-2015-0848
    CVE-2015-4588
    CVE-2015-4695
    CVE-2015-4696
    RHSA-2015:1917
    RHSA-2015:1917-00
    RHSA-2015:1917-01
    Platform(s):Red Hat Enterprise Linux 6
    Red Hat Enterprise Linux 7
    Product(s):
    Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 6 is installed
  • AND
  • libwmf is earlier than 0:0.2.8.4-25.el6_7
  • AND libwmf is signed with Red Hat redhatrelease2 key
  • libwmf-devel is earlier than 0:0.2.8.4-25.el6_7
  • AND libwmf-devel is signed with Red Hat redhatrelease2 key
  • libwmf-lite is earlier than 0:0.2.8.4-25.el6_7
  • AND libwmf-lite is signed with Red Hat redhatrelease2 key
  • OR Package Information
  • Red Hat Enterprise Linux 7 is installed
  • AND
  • libwmf is earlier than 0:0.2.8.4-41.el7_1
  • AND libwmf is signed with Red Hat redhatrelease2 key
  • libwmf-devel is earlier than 0:0.2.8.4-41.el7_1
  • AND libwmf-devel is signed with Red Hat redhatrelease2 key
  • libwmf-lite is earlier than 0:0.2.8.4-41.el7_1
  • AND libwmf-lite is signed with Red Hat redhatrelease2 key
  • Definition Synopsis
  • Release Information
  • Red Hat Enterprise Linux 6 Client is installed
  • OR Red Hat Enterprise Linux 6 Server is installed
  • OR Red Hat Enterprise Linux 6 Workstation is installed
  • OR Red Hat Enterprise Linux 6 ComputeNode is installed
  • AND
  • libwmf is earlier than 0:0.2.8.4-25.el6_7
  • AND libwmf is signed with Red Hat redhatrelease2 key
  • libwmf-devel is earlier than 0:0.2.8.4-25.el6_7
  • AND libwmf-devel is signed with Red Hat redhatrelease2 key
  • libwmf-lite is earlier than 0:0.2.8.4-25.el6_7
  • AND libwmf-lite is signed with Red Hat redhatrelease2 key
  • OR Package Information
  • Red Hat Enterprise Linux 7 Client is installed
  • OR Red Hat Enterprise Linux 7 Server is installed
  • OR Red Hat Enterprise Linux 7 Workstation is installed
  • OR Red Hat Enterprise Linux 7 ComputeNode is installed
  • AND
  • libwmf is earlier than 0:0.2.8.4-41.el7_1
  • AND libwmf is signed with Red Hat redhatrelease2 key
  • libwmf-devel is earlier than 0:0.2.8.4-41.el7_1
  • AND libwmf-devel is signed with Red Hat redhatrelease2 key
  • libwmf-lite is earlier than 0:0.2.8.4-41.el7_1
  • AND libwmf-lite is signed with Red Hat redhatrelease2 key
  • BACK