Submitted by KeesCook on Wed, 2006-11-29 12:07
Referenced CVEs:
CVE-2006-6120
Description:
===========================================================
Ubuntu Security Notice USN-388-1 November 29, 2006
koffice vulnerability
CVE-2006-6120
===========================================================
A security issue affects the following Ubuntu releases:
Ubuntu 5.10
This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.
The problem can be corrected by upgrading your system to the
following package versions:
Ubuntu 5.10:
koffice-libs 1:1.4.1-0ubuntu7.4
After a standard system upgrade you need to restart your Desktop session
to effect the necessary changes.
Details follow:
An integer overflow was discovered in KOffice's filtering code. By
tricking a user into opening a specially crafted PPT file, attackers
could crash KOffice or possibly execute arbitrary code with the user's
privileges.


