Dit bericht is nog niet vertaald

[USN-603-2] KOffice vulnerability

Ubuntu Security Notice USN-603-2             April 17, 2008
koffice vulnerability
CVE-2008-1693
Kwetsbare Ubuntu versies:

Ubuntu 6.06 LTS
Ubuntu 6.10
Ubuntu 7.04
Ubuntu 7.10

Kwetsbare pakketten:

Ubuntu 6.06 LTS
kword 1:1.5.0-0ubuntu9.4
Ubuntu 6.10
kword 1:1.5.2-0ubuntu2.4
Ubuntu 7.10
kword 1:1.6.3-0ubuntu5.2
Ubuntu 7.04
kword 1:1.6.2-0ubuntu1.3

After a standard system upgrade you need to restart KWord to effect the necessary changes.

USN-603-1 fixed vulnerabilities in poppler. This update provides the corresponding updates for KWord, part of KOffice. Original advisory details: It was discovered that the poppler PDF library did not correctly handle certain malformed embedded fonts. If a user or an automated system were tricked into opening a malicious PDF, a remote attacker could execute arbitrary code with user privileges.