Submitted by MarcDeslauriers on Thu, 2009-05-07 18:30
Referenced CVEs:
CVE-2009-0757
Description:
===========================================================
Ubuntu Security Notice USN-772-1 May 07, 2009
mpfr vulnerability
CVE-2009-0757
===========================================================
A security issue affects the following Ubuntu releases:
Ubuntu 9.04
This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.
The problem can be corrected by upgrading your system to the
following package versions:
Ubuntu 9.04:
lib64mpfr1 2.4.0-1ubuntu3.1
libmpfr1ldbl 2.4.0-1ubuntu3.1
In general, a standard system upgrade is sufficient to effect the
necessary changes.
Details follow:
It was discovered that MPFR improperly handled string lengths in its print
routines. If a user or automated system were tricked into processing
specially crafted data with applications linked against MPFR, an attacker
could cause a denial of service or execute arbitrary code with privileges
of the user invoking the program.


