It was discovered that libwmf did not properly process certain WMF files. By tricking a victim into opening a specially crafted WMF file in an application using libwmf, a remote attacker could possibly exploit this flaw to cause a crash or execute arbitrary code with the privileges of the user running the application.
Find out more about CVE-2015-4695 from the MITRE CVE dictionary dictionary and NIST NVD.
Base Score | 2.6 |
---|---|
Base Metrics | AV:N/AC:H/Au:N/C:P/I:N/A:N |
Access Vector | Network |
Access Complexity | High |
Authentication | None |
Confidentiality Impact | Partial |
Integrity Impact | None |
Availability Impact | None |
Find out more about Red Hat support for the Common Vulnerability Scoring System (CVSS).
Platform | Errata | Release Date |
---|---|---|
Red Hat Enterprise Linux 6 (libwmf) | RHSA-2015:1917 | 2015-10-20 |
Red Hat Enterprise Linux 7 (libwmf) | RHSA-2015:1917 | 2015-10-20 |
Platform | Package | State |
---|---|---|
Red Hat Enterprise Linux 5 | libwmf | Will not fix |