-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------- Debian Security Advisory DSA-3302-1 security@xxxxxxxxxx https://www.debian.org/security/ Moritz Muehlenhoff July 06, 2015 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : libwmf CVE ID : CVE-2015-0848 CVE-2015-4588 CVE-2015-4695 CVE-2015-4696 Insufficient input sanitising in libwmf, a library to process Windows metafile data, may result in denial of service or the execution of arbitrary code if a malformed WMF file is opened. For the oldstable distribution (wheezy), these problems have been fixed in version 0.2.8.4-10.3+deb7u1. For the stable distribution (jessie), these problems have been fixed in version 0.2.8.4-10.3+deb8u1. For the unstable distribution (sid), these problems will be fixed soon. We recommend that you upgrade your libwmf packages. Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: debian-security-announce@xxxxxxxxxxxxxxxx -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIcBAEBAgAGBQJVmuviAAoJEBDCk7bDfE42fFEP/1zDnj23DcAk4rlmDzvdRwEC hETr0DcvBMWw3nzBYQ7IYO7nH1vKJmsomLwsiu52EA6mUYJckdQ/4qr3mcE4Agm/ JwnvAY7TYeNKICrhiza+DEnQYk2CRmy1LdgrvhLv2QEyyRclc8WlimSB3T6dbiwC wjWCrI3SA1ud7NT//aRRJ0NUc9Q1w/V84/coRt+yvzSV8dMuunj5SSzm8KA7qNm2 jQWPq6Kh0/LnlLPvyq8Nr5bEc8ng3Nh336sGuKs/BhObi2iSlgiqdehzD6VUG8Hu wzcTdQ/AMofILoAm+sBw8Akxu80oanShdITfwpC7i22LzQdDJWRQFOJqPCIGbsLu IF2y1SP93Bd4f9rk/yhzzjImdcUCPdJLflO1XVW5+qsRy1dUFHBe8aqCZHBsLVqm Gd5yah68awXHH/PSWEO4cDtoiJq3iBfvKVqO3Ur1ceX9MuS3Z5udIz8Yrq8mmi9g olO8tVsPKfYe5kwIRi5S71ustYLHmdJ9CUHl7tMQ6LrSXAUybSnZHy8bK77hcRe2 LL0Src4ioCljR8gTYKAxMtKt0s2dyjGVACh9ScGcQZIMH9JueZnXsj9hURAsu1Jn kB3nWB1UxmOzsEjGZ/ud2yCBYO4I5oAW1QJmGj4FYH1rt3LtwYeMz5YnB3BuugVS miSRB5gn5FyaIT+I3iTY =hkJ/ -----END PGP SIGNATURE-----