Related Vulnerabilities: CVE-2009-1364  

Use-after-free vulnerability in the embedded GD library in libwmf 0.2.8.4 allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted WMF file.

Severity Critical

Remote Yes

Type Arbitrary code execution

Description

Use-after-free vulnerability in the embedded GD library in libwmf 0.2.8.4 allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted WMF file.

AVG-16 libwmf 0.2.8.4-13 0.2.8.4-14 Critical Fixed FS#49162

01 Jan 2017 ASA-201701-1 AVG-16 libwmf Critical multiple issues