Jump to content
Flubber

Ubuntu Security Notice USN-1035-1

Recommended Posts

A security issue affects the following Ubuntu releases:

Ubuntu 8.04 LTS

Ubuntu 9.10

Ubuntu 10.04 LTS

Ubuntu 10.10

This advisory also applies to the corresponding versions of

Kubuntu, Edubuntu, and Xubuntu.

The problem can be corrected by upgrading your system to the

following package versions:

Ubuntu 8.04 LTS:

evince 2.22.2-0ubuntu2.1

Ubuntu 9.10:

evince 2.28.1-0ubuntu1.3

Ubuntu 10.04 LTS:

evince 2.30.3-0ubuntu1.2

Ubuntu 10.10:

evince 2.32.0-0ubuntu1.1

Detalii:


Details follow:

Jon Larimer discovered that Evince's font parsers incorrectly handled
certain buffer lengths when rendering a DVI file. By tricking a user into
opening or previewing a DVI file that uses a specially crafted font file,
an attacker could crash evince or execute arbitrary code with the user's
privileges.

In the default installation of Ubuntu 9.10 and later, attackers would be
isolated by the Evince AppArmor profile.

Sursa: Full Disclosure: [uSN-1035-1] Evince vulnerabilities

Patch-urile au fost deja lansate (cu cateva ore in urma) asa ca, go, go apt-get:

sudo apt-get update

&&

sudo apt-get upgrade

Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.



×
×
  • Create New...