Severity Critical
Remote Yes
Type Arbitrary code execution
It was discovered that libwmf did not correctly process certain WMF (Windows Metafiles) containing BMP images. By tricking a victim into opening a specially crafted WMF file in an application using libwmf, a remote attacker could possibly use this flaw to execute arbitrary code with the privileges of the user running the application.
Group Package Affected Fixed Severity Status Ticket
AVG-16 libwmf Critical Fixed FS#49162
Date Advisory Group Package Severity Description
01 Jan 2017 ASA-201701-1 AVG-16 libwmf Critical multiple issues