CVE-2020-13999

MEDIUM

libemf < 1.0.12 - Integer Overflow and Denial of Service via ScaleViewPortExtEx

Title source: llm
STIX 2.1

Description

ScaleViewPortExtEx in libemf.cpp in libEMF (aka ECMA-234 Metafile Library) 1.0.12 allows an integer overflow and denial of service via a crafted EMF file.

References (6)

Core 6
Core References
Product, Third Party Advisory x_refsource_misc
http://libemf.sourceforge.net/index.html
Third Party Advisory x_refsource_misc
https://sourceforge.net/projects/libemf/
Third Party Advisory x_refsource_misc
https://sourceforge.net/p/libemf/code/HEAD/tree/

Scores

CVSS v3 5.5
EPSS 0.0121
EPSS Percentile 64.6%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

Details

CWE
CWE-190
Status published
Products (3)
fedoraproject/fedora 31
fedoraproject/fedora 32
libemf_project/libemf < 1.0.12
Published Jun 15, 2020
Tracked Since Feb 18, 2026