Description
libEMF (aka ECMA-234 Metafile Library) through 1.0.11 allows denial of service (issue 1 of 2).
References (5)
Core 5
Core References
Third Party Advisory x_refsource_misc
https://sourceforge.net/p/libemf/mailman/libemf-devel/
Third Party Advisory x_refsource_misc
https://sourceforge.net/p/libemf/code/commit_browser
Patch, Release Notes, Third Party Advisory x_refsource_misc
https://sourceforge.net/p/libemf/news/2020/05/re-release-of-libemf-1012/
Mailing List, Third Party Advisory vendor-advisory
x_refsource_fedora
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2DFYDSKWFM2R5NKZOO2IN6X7SM3T2PWL/
Third Party Advisory vendor-advisory
x_refsource_suse
http://lists.opensuse.org/opensuse-security-announce/2020-06/msg00036.html
Scores
CVSS v3
5.5
EPSS
0.0044
EPSS Percentile
63.2%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Details
Status
published
Products (3)
fedoraproject/fedora
31
libemf_project/libemf
< 1.0.11
opensuse/leap
15.1
Published
May 11, 2020
Tracked Since
Feb 18, 2026