7.5
CVSSv2

CVE-2006-0106

Published: 06/01/2006 Updated: 19/10/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

gdi/driver.c and gdi/printdrv.c in Wine 20050930, and other versions, implement the SETABORTPROC GDI Escape function call for Windows Metafile (WMF) files, which allows malicious users to execute arbitrary code, the same vulnerability as CVE-2005-4560 but in a different codebase.

Vulnerable Product Search on Vulmon Subscribe to Product

wine wine 0.9.4

wine wine 0.9.5

wine wine 2005-09-30

wine wine 0.9.2

Vendor Advisories

Debian Bug report logs - #346197 [CVE-2006-0106] Wine is vulnerable to SetAbortProc WMF bug Package: wine; Maintainer for wine is Debian Wine Party <debian-wine@listsdebianorg>; Source for wine is src:wine (PTS, buildd, popcon) Reported by: Florian Weimer <fw@denebenyode> Date: Fri, 6 Jan 2006 10:18:01 UTC Seve ...
H D Moore has discovered that Wine, a free implementation of the Microsoft Windows APIs, inherits a design flaw from the Windows GDI API, which may lead to the execution of code through GDI escape functions in WMF files The old stable distribution (woody) does not seem to be affected by this problem For the stable distribution (sarge) this proble ...