ScaleViewPortExtEx in libemf.cpp in libEMF (aka ECMA-234 Metafile Library) 1.0.12 allows an integer overflow and denial of service via a crafted EMF file.
References
Link | Resource |
---|---|
https://sourceforge.net/p/libemf/news/2020/06/release-of-libemf-1013/ | Third Party Advisory |
http://libemf.sourceforge.net/index.html | Product Third Party Advisory |
https://sourceforge.net/projects/libemf/ | Third Party Advisory |
https://sourceforge.net/p/libemf/code/HEAD/tree/ | Third Party Advisory |
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/CVZXYNDM4YOONMXYPW2GTMIS6V6JBIL6/ | Mailing List Third Party Advisory |
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/555PIBSHDUZD26UCJ5DHCQ4W7RXEZC66/ | Mailing List Third Party Advisory |
Information
Published : 2020-06-15 09:15
Updated : 2023-01-27 10:58
NVD link : CVE-2020-13999
Mitre link : CVE-2020-13999
JSON object : View
CWE
CWE-190
Integer Overflow or Wraparound
Products Affected
libemf_project
- libemf
fedoraproject
- fedora