USN-437-1: libwpd vulnerability

Ubuntu Security Notice USN-437-1

19th March, 2007

libwpd vulnerability

A security issue affects these releases of Ubuntu and its derivatives:

  • Ubuntu 6.10
  • Ubuntu 6.06 LTS
  • Ubuntu 5.10

Details

Sean Larsson of iDefense Labs discovered that libwpd was vulnerable to
integer overflows. If a user were tricked into opening a specially
crafted WordPerfect document with an application that used libwpd, an
attacker could execute arbitrary code with user privileges.

Update instructions

The problem can be corrected by updating your system to the following package version:

Ubuntu 6.10:
libwpd8c2a 0.8.6-1ubuntu0.1
Ubuntu 6.06 LTS:
libwpd8c2a 0.8.4-2ubuntu0.1
Ubuntu 5.10:
libwpd8c2 0.8.2-2ubuntu0.1

To update your system, please follow these instructions: https://wiki.ubuntu.com/Security/Upgrades.

In general, a standard system upgrade is sufficient to effect the
necessary changes.

References

CVE-2007-0002