Submitted by KeesCook on Mon, 2006-12-04 12:07
Referenced CVEs:
CVE-2006-4514
Description:
===========================================================
Ubuntu Security Notice USN-391-1 December 04, 2006
libgsf vulnerability
CVE-2006-4514
===========================================================
A security issue affects the following Ubuntu releases:
Ubuntu 5.10
Ubuntu 6.06 LTS
Ubuntu 6.10
This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.
The problem can be corrected by upgrading your system to the
following package versions:
Ubuntu 5.10:
libgsf-1 1.12.3-3ubuntu3.1
Ubuntu 6.06 LTS:
libgsf-1-113 1.13.99-0ubuntu2.1
Ubuntu 6.10:
libgsf-1-114 1.14.1-2ubuntu1.1
After a standard system upgrade you need to restart your desktop session
to effect the necessary changes.
Details follow:
A heap overflow was discovered in the OLE processing code in libgsf. If
a user were tricked into opening a specially crafted OLE document, an
attacker could execute arbitrary code with the user's privileges.


