libwmf is a library for reading and converting Windows Metafile Format (WMF) vector graphics. libwmf is used by applications such as GIMP and ImageMagick. It was discovered that libwmf did not correctly process certain WMF (Windows Metafiles) with embedded BMP images. By tricking a victim into opening a specially crafted WMF file in an application using libwmf, a remote attacker could possibly use this flaw to execute arbitrary code with the privileges of the user running the application. (CVE-2015-0848, CVE-2015-4588) It was discovered that libwmf did not properly process certain WMF files. By tricking a victim into opening a specially crafted WMF file in an application using libwmf, a remote attacker could possibly exploit this flaw to cause a crash or execute arbitrary code with the privileges of the user running the application. (CVE-2015-4696) It was discovered that libwmf did not properly process certain WMF files. By tricking a victim into opening a specially crafted WMF file in an application using libwmf, a remote attacker could possibly exploit this flaw to cause a crash. (CVE-2015-4695) All users of libwmf are advised to upgrade to these updated packages, which contain backported patches to correct these issues. After installing the update, all applications using libwmf must be restarted for the update to take effect.
lists.fedoraproject.org/pipermail/package-announce/2015-July/162569.html
lists.opensuse.org/opensuse-updates/2015-07/msg00018.html
rhn.redhat.com/errata/RHSA-2015-1917.html
www.debian.org/security/2015/dsa-3302
www.openwall.com/lists/oss-security/2015/06/17/3
www.openwall.com/lists/oss-security/2015/06/21/3
www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.html
www.securityfocus.com/bid/75331
www.securitytracker.com/id/1032771
www.ubuntu.com/usn/USN-2670-1
access.redhat.com/security/updates/classification/#important
bugs.debian.org/cgi-bin/bugreport.cgi?bug=784192
rhn.redhat.com/errata/RHSA-2015-1917.html
security.gentoo.org/glsa/201602-03