Submitted by KeesCook on Mon, 2007-12-03 21:41
Referenced CVEs:
CVE-2007-5503
Description:
===========================================================
Ubuntu Security Notice USN-550-1 December 03, 2007
libcairo vulnerability
CVE-2007-5503
===========================================================
A security issue affects the following Ubuntu releases:
Ubuntu 6.06 LTS
Ubuntu 6.10
Ubuntu 7.04
Ubuntu 7.10
This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.
The problem can be corrected by upgrading your system to the
following package versions:
Ubuntu 6.06 LTS:
libcairo2 1.0.4-0ubuntu1.1
Ubuntu 6.10:
libcairo2 1.2.4-1ubuntu2.1
Ubuntu 7.04:
libcairo2 1.4.2-0ubuntu1.1
Ubuntu 7.10:
libcairo2 1.4.10-1ubuntu4.1
After a standard system upgrade you need to restart your session to effect
the necessary changes.
Details follow:
Peter Valchev discovered that Cairo did not correctly decode PNG image data.
By tricking a user or automated system into processing a specially crafted
PNG with Cairo, a remote attacker could execute arbitrary code with user
privileges.


