USN-138-1: gedit vulnerability

Ubuntu Security Notice USN-138-1

9th June, 2005

gedit vulnerability

A security issue affects these releases of Ubuntu and its derivatives:

  • Ubuntu 5.04
  • Ubuntu 4.10

Details

A format string vulnerability has been discovered in gedit. Calling
the program with specially crafted file names caused a buffer
overflow, which could be exploited to execute arbitrary code with the
privileges of the gedit user.

This becomes security relevant if e. g. your web browser is configued
to open URLs in gedit. If you never open untrusted file names or URLs
in gedit, this flaw does not affect you.

Update instructions

The problem can be corrected by updating your system to the following package version:

Ubuntu 5.04:
gedit
Ubuntu 4.10:
gedit

To update your system, please follow these instructions: https://wiki.ubuntu.com/Security/Upgrades.

None

References

CVE-2005-1686