Dit bericht is nog niet vertaald

[USN-604-1] Gnumeric vulnerability

Ubuntu Security Notice USN-604-1             April 22, 2008
gnumeric vulnerability
CVE-2008-0668
Kwetsbare Ubuntu versies:

Ubuntu 6.06 LTS
Ubuntu 6.10
Ubuntu 7.04
Ubuntu 7.10

Kwetsbare pakketten:

Ubuntu 6.06 LTS
gnumeric 1.6.3-0ubuntu4.1
Ubuntu 6.10
gnumeric 1.7.0-1ubuntu4.1
Ubuntu 7.10
gnumeric 1.7.11-1ubuntu3.1
Ubuntu 7.04
gnumeric 1.7.8-0ubuntu1.1

After a standard system upgrade you need to restart gnumeric to effect the necessary changes.

Thilo Pfennig and Morten Welinder discovered that the XLS spreadsheet handling code in Gnumeric did not correctly calculate needed memory sizes. If a user or automated system were tricked into loading a specially crafted XLS document, a remote attacker could execute arbitrary code with user privileges.