Submitted by MarcDeslauriers on Thu, 2009-03-26 19:32
Referenced CVEs:
CVE-2008-1036
Description:
===========================================================
Ubuntu Security Notice USN-747-1 March 26, 2009
icu vulnerability
CVE-2008-1036
===========================================================
A security issue affects the following Ubuntu releases:
Ubuntu 6.06 LTS
Ubuntu 7.10
Ubuntu 8.04 LTS
Ubuntu 8.10
This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.
The problem can be corrected by upgrading your system to the
following package versions:
Ubuntu 6.06 LTS:
libicu34 3.4.1a-1ubuntu1.6.06.2
Ubuntu 7.10:
libicu36 3.6-3ubuntu0.2
Ubuntu 8.04 LTS:
libicu38 3.8-6ubuntu0.1
Ubuntu 8.10:
libicu38 3.8.1-2ubuntu0.1
After a standard system upgrade you need to restart applications linked
against libicu, such as OpenOffice.org, to effect the necessary changes.
Details follow:
It was discovered that libicu did not correctly handle certain invalid
encoded data. If a user or automated system were tricked into processing
specially crafted data with applications linked against libicu, certain
content filters could be bypassed.


