Submitted by KeesCook on Wed, 2008-01-09 05:36
Referenced CVEs:
CVE-2007-4897
Description:
===========================================================
Ubuntu Security Notice USN-561-1 January 08, 2008
pwlib vulnerability
CVE-2007-4897
===========================================================
A security issue affects the following Ubuntu releases:
Ubuntu 6.06 LTS
Ubuntu 6.10
Ubuntu 7.04
Ubuntu 7.10
This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.
The problem can be corrected by upgrading your system to the
following package versions:
Ubuntu 6.06 LTS:
libpt-1.10.0 1.10.0-1ubuntu1.1
Ubuntu 6.10:
libpt-1.10.0 1.10.2.dfsg-0ubuntu3.1
Ubuntu 7.04:
libpt-1.10.0 1.10.3-0ubuntu1.1
Ubuntu 7.10:
libpt-1.10.0 1.10.10-0ubuntu2.1
After a standard system upgrade you need to restart your session to effect
the necessary changes.
Details follow:
Jose Miguel Esparza discovered that pwlib did not correctly handle large
string lengths. A remote attacker could send specially crafted packets to
applications linked against pwlib (e.g. Ekiga) causing them to crash, leading
to a denial of service.


