bk99.de entertain the web since 1997

Linux also vulnerable to the WMF security hole through Wine

Summary

In January 2006 the WMF hole, through which manipulated image files executed code under Windows, also affected Wine, Cedega and CrossOver Office. According to HD Moore, author of the proof of concept, the complete metafile API had been recreated in Wine, including the bug. Not only Windows code but also native shellcode could be executed, and Marcus Meissner of SUSE supplied a patch.

Ideas

  • A faithful recreation of an API also takes over its design flaws.
  • An image embedded in a Word document could trigger malicious code.
  • Compatibility layers make Linux vulnerable to Windows holes.

Insights

  • Compatibility sometimes means copying bugs, deliberately or not.
  • The platform offers no protection if the application layer has the same hole.

Facts

  • Wine, Cedega and CrossOver Office were affected.
  • The patch came from Marcus Meissner (SUSE).
  • According to F-Secure, the WMF format from the 1980s explicitly provided for executable code in images.

References

Critique

  • The report is based on a forwarded email and names no affected Wine versions.

Recommendations

  • Keep Wine and environments built on it, such as Proton, as up to date as Windows.
  • Do not open documents of unknown origin with Windows programs in Wine on Linux either.

Read the original article

Search the Web Archive