The OpenNET Project
 
Search (keywords):  SOFT ARTICLES TIPS & TRICKS SECURITY
LINKS NEWS MAN DOCUMENTATION


[KOffice security advisory] KOffice OLEfilter integer overflow


<< Previous INDEX Search src / Print Next >>
From: Dirk Mueller <mueller@kde.org.>
To: [email protected]
Subject: [KOffice security advisory] KOffice OLEfilter integer overflow
Date: Tue, 5 Dec 2006 11:49:11 +0100
User-Agent: KMail/1.9.5
Cc: [email protected]
MIME-Version: 1.0
Content-Type: text/plain;
  charset="us-ascii"
Content-Transfer-Encoding: 7bit
Content-Disposition: inline
Message-Id: <200612051149.11715.mueller@kde.org.>
X-Virus-Scanned: antivirus-gw at tyumen.ru


KOffice Security Advisory: KOffice olefilters integer overflow
Original Release Date: 2006-12-04
URL: http://www.kde.org/info/security/advisory-20061204-1.txt

0. References

        CVE-2006-6120


1. Systems affected:

        KOffice 1.4.x and 1.6.0. 1.5.x releases are unaffected as well
        as 1.6.1 or newer.


2. Overview:

        The OLE import filter, which is used in KPresenter to open Microsoft
        Powerpoint files is vulnerable to an integer overflow problem that
        can be exploited to expose an heap memory overflow.  This
        issue was reported by Kees Cook from Ubuntu security.


3. Impact:

        A maliciously crafted file can cause to execute arbitrary code.


4. Solution:

        Source code patches have been made available which fix these
        vulnerabilities. Contact your OS vendor / binary package provider
        fo information about how to obtain updated binary packages.


5. Patch:

        A patch for KOffice 1.4.0 - KOffice 1.6.0 is available from
        ftp://ftp.kde.org/pub/kde/security_patches :

        20dff20ccd2e184f1874aa60d85f4380  post-koffice-1.6.0.diff


<< Previous INDEX Search src / Print Next >>



Партнёры:
PostgresPro
Inferno Solutions
Hosting by Hoster.ru
Хостинг:

Закладки на сайте
Проследить за страницей
Created 1996-2025 by Maxim Chirkov
Добавить, Поддержать, Вебмастеру