Submitted by MartinPitt on Fri, 2007-08-03 10:40
Referenced CVEs:
CVE-2007-3387
Description:
===========================================================
Ubuntu Security Notice USN-496-1 August 03, 2007
koffice vulnerability
CVE-2007-3387
===========================================================
A security issue affects the following Ubuntu releases:
Ubuntu 6.06 LTS
Ubuntu 6.10
Ubuntu 7.04
This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.
The problem can be corrected by upgrading your system to the
following package versions:
Ubuntu 6.06 LTS:
kword 1:1.5.0-0ubuntu9.2
Ubuntu 6.10:
kword 1:1.5.2-0ubuntu2.2
Ubuntu 7.04:
kword 1:1.6.2-0ubuntu1.1
After a standard system upgrade you need to restart KWord to effect
the necessary changes.
Details follow:
Derek Noonburg discovered an integer overflow in the Xpdf function
StreamPredictor::StreamPredictor(). By importing a specially crafted
PDF file into KWord, this could be exploited to run arbitrary code
with the user's privileges.


