Zum Inhalt springen.
Sympa Menü

it-securitynotifies - [IT-SecNots] [SECURITY] [DSA 3302-1] libwmf security update

it-securitynotifies AT lists.piratenpartei.de

Betreff: Sicherheitsankündigungen

Listenarchiv

[IT-SecNots] [SECURITY] [DSA 3302-1] libwmf security update


Chronologisch Thread 
  • From: Moritz Muehlenhoff <jmm AT debian.org>
  • To: debian-security-announce AT lists.debian.org
  • Subject: [IT-SecNots] [SECURITY] [DSA 3302-1] libwmf security update
  • Date: Mon, 6 Jul 2015 22:58:53 +0200
  • List-archive: <https://service.piratenpartei.de/pipermail/it-securitynotifies>
  • List-id: Sicherheitsankündigungen <it-securitynotifies.lists.piratenpartei.de>
  • Old-return-path: <jmm AT inutil.org>
  • Priority: urgent
  • Resent-date: Mon, 6 Jul 2015 20:59:25 +0000 (UTC)
  • Resent-from: debian-security-announce AT lists.debian.org
  • Resent-message-id: <vmnDEF4ZWFL.A.bK.twumVB@bendel>
  • Resent-sender: debian-security-announce-request AT lists.debian.org

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

- -------------------------------------------------------------------------
Debian Security Advisory DSA-3302-1 security AT debian.org
https://www.debian.org/security/ Moritz Muehlenhoff
July 06, 2015 https://www.debian.org/security/faq
- -------------------------------------------------------------------------

Package : libwmf
CVE ID : CVE-2015-0848 CVE-2015-4588 CVE-2015-4695 CVE-2015-4696

Insufficient input sanitising in libwmf, a library to process Windows
metafile data, may result in denial of service or the execution of
arbitrary code if a malformed WMF file is opened.

For the oldstable distribution (wheezy), these problems have been fixed
in version 0.2.8.4-10.3+deb7u1.

For the stable distribution (jessie), these problems have been fixed in
version 0.2.8.4-10.3+deb8u1.

For the unstable distribution (sid), these problems will be fixed soon.

We recommend that you upgrade your libwmf packages.

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/

Mailing list: debian-security-announce AT lists.debian.org
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1

iQIcBAEBAgAGBQJVmuviAAoJEBDCk7bDfE42fFEP/1zDnj23DcAk4rlmDzvdRwEC
hETr0DcvBMWw3nzBYQ7IYO7nH1vKJmsomLwsiu52EA6mUYJckdQ/4qr3mcE4Agm/
JwnvAY7TYeNKICrhiza+DEnQYk2CRmy1LdgrvhLv2QEyyRclc8WlimSB3T6dbiwC
wjWCrI3SA1ud7NT//aRRJ0NUc9Q1w/V84/coRt+yvzSV8dMuunj5SSzm8KA7qNm2
jQWPq6Kh0/LnlLPvyq8Nr5bEc8ng3Nh336sGuKs/BhObi2iSlgiqdehzD6VUG8Hu
wzcTdQ/AMofILoAm+sBw8Akxu80oanShdITfwpC7i22LzQdDJWRQFOJqPCIGbsLu
IF2y1SP93Bd4f9rk/yhzzjImdcUCPdJLflO1XVW5+qsRy1dUFHBe8aqCZHBsLVqm
Gd5yah68awXHH/PSWEO4cDtoiJq3iBfvKVqO3Ur1ceX9MuS3Z5udIz8Yrq8mmi9g
olO8tVsPKfYe5kwIRi5S71ustYLHmdJ9CUHl7tMQ6LrSXAUybSnZHy8bK77hcRe2
LL0Src4ioCljR8gTYKAxMtKt0s2dyjGVACh9ScGcQZIMH9JueZnXsj9hURAsu1Jn
kB3nWB1UxmOzsEjGZ/ud2yCBYO4I5oAW1QJmGj4FYH1rt3LtwYeMz5YnB3BuugVS
miSRB5gn5FyaIT+I3iTY
=hkJ/
-----END PGP SIGNATURE-----


--
To UNSUBSCRIBE, email to debian-security-announce-REQUEST AT lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmaster AT lists.debian.org
Archive: https://lists.debian.org/20150706205853.GA27673 AT pisco.westfalen.local




  • [IT-SecNots] [SECURITY] [DSA 3302-1] libwmf security update, Moritz Muehlenhoff, 06.07.2015

Archiv bereitgestellt durch MHonArc 2.6.19.

Seitenanfang