USN-202-1: KOffice vulnerability

12 October 2005

koffice vulnerability

A security issue affects these releases of Ubuntu and its derivatives:

  • Ubuntu 5.04

Software Description

Details

Chris Evans discovered a buffer overflow in the RTF import module of KOffice. By tricking a user into opening a specially-crafted RTF file, an attacker could exploit this to execute arbitrary code with the privileges of the AbiWord user.

Update instructions

The problem can be corrected by updating your system to the following package versions:

Ubuntu 5.04
koffice-libs
kword

To update your system, please follow these instructions: https://wiki.ubuntu.com/Security/Upgrades.

References