Uncontrolled memory allocation in libwmf - CVE-2016-9011

 

Uncontrolled memory allocation in libwmf - CVE-2016-9011

Published: May 2, 2018


Vulnerability identifier: #VU12353
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-9011
CWE-ID: CWE-789
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause DoS condition on the target system.

The weakness exists in the wmf_malloc function in api.c due to uncontrolled memory allocation. A remote attacker can trick the victim into opening a specially crafted wmf file, trigger memory corruption and cause the service to crash.


Affected software

libwmf
SUSE Linux Enterprise Workstation Extension
SUSE Linux Enterprise Software Development Kit
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Server
SUSE Linux Enterprise Desktop
Slackware Linux
SUSE Linux Enterprise High Performance Computing
openSUSE Leap
SUSE Linux Enterprise Module for Packagehub Subpackages
libwmf-tools-debuginfo
libwmf-tools
libwmf-gnome-debuginfo
libwmf-gnome
libwmf-devel
libwmf-debugsource
libwmf-0_2-7-debuginfo
libwmf-0_2-7
libwmf-gnome-32bit
libwmf-gnome-32bit-debuginfo
libwmf-0_2-7-32bit-debuginfo
libwmf-0_2-7-32bit

How to mitigate CVE-2016-9011

Install update from vendor's website.

libwmf-tools-debuginfo - addressed in versions 0.2.12-243.3.1, 0.2.12-150000.4.4.1
libwmf-tools - addressed in versions 0.2.12-243.3.1, 0.2.12-150000.4.4.1
libwmf-gnome-debuginfo - addressed in versions 0.2.12-243.3.1, 0.2.12-150000.4.4.1
libwmf-gnome - addressed in versions 0.2.12-243.3.1, 0.2.12-150000.4.4.1
libwmf-devel - addressed in versions 0.2.12-243.3.1, 0.2.12-150000.4.4.1
libwmf-debugsource - addressed in versions 0.2.12-243.3.1, 0.2.12-150000.4.4.1
libwmf-0_2-7-debuginfo - addressed in versions 0.2.12-243.3.1, 0.2.12-150000.4.4.1
libwmf-0_2-7 - addressed in versions 0.2.12-243.3.1, 0.2.12-150000.4.4.1
libwmf-gnome-32bit - update to 0.2.12-150000.4.4.1
libwmf-gnome-32bit-debuginfo - update to 0.2.12-150000.4.4.1
libwmf-0_2-7-32bit-debuginfo - update to 0.2.12-150000.4.4.1
libwmf-0_2-7-32bit - update to 0.2.12-150000.4.4.1

External References

Related Security Bulletins