Oval Definition:oval:org.mitre.oval:def:7858
Revision Date:2015-02-23Version:21
Title:DSA-1509 koffice -- multiple vulnerabilities
Description:Several vulnerabilities have been discovered in xpdf code that is embedded in koffice, an integrated office suite for KDE. These flaws could allow an attacker to execute arbitrary code by inducing the user to import a specially crafted PDF document. The Common Vulnerabilities and Exposures project identifies the following problems: Array index error in the DCTStream::readProgressiveDataUnit method in xpdf/Stream.cc in Xpdf 3.02pl1, as used in poppler, teTeX, KDE, KOffice, CUPS, and other products, allows remote attackers to trigger memory corruption and execute arbitrary code via a crafted PDF file. Integer overflow in the DCTStream::reset method in xpdf/Stream.cc in Xpdf 3.02p11 allows remote attackers to execute arbitrary code via a crafted PDF file, resulting in a heap-based buffer overflow. Heap-based buffer overflow in the CCITTFaxStream::lookChar method in xpdf/Stream.cc in Xpdf 3.02p11 allows remote attackers to execute arbitrary code via a PDF file that contains a crafted CCITTFaxDecode filter. Updates for the old stable distribution (sarge) will be made available as soon as possible.
Family:unixClass:patch
Status:ACCEPTEDReference(s):CVE-2007-4352
CVE-2007-5392
CVE-2007-5393
DSA-1509
Platform(s):Debian GNU/Linux 4.0
Product(s):koffice
Definition Synopsis
  • Debian GNU/Linux 4.0 is installed.
  • AND Architecture section
  • Architecture independent section
  • Installed architecture is all
  • AND Packages section
  • krita-data is earlier than 1:1.6.1-2etch2
  • OR koffice-doc is earlier than 1:1.6.1-2etch2
  • OR koffice is earlier than 1:1.6.1-2etch2
  • OR koffice-doc-html is earlier than 1:1.6.1-2etch2
  • OR kivio-data is earlier than 1:1.6.1-2etch2
  • OR koffice-data is earlier than 1:1.6.1-2etch2
  • OR kword-data is earlier than 1:1.6.1-2etch2
  • OR kpresenter-data is earlier than 1:1.6.1-2etch2
  • OR Architecture dependent section
  • Supported architectures section
  • Installed architecture is s390
  • OR Installed architecture is amd64
  • OR Installed architecture is sparc
  • OR Installed architecture is powerpc
  • OR Installed architecture is i386
  • OR Installed architecture is alpha
  • OR Installed architecture is mips
  • OR Installed architecture is hppa
  • AND Packages section
  • kpresenter is earlier than 1:1.6.1-2etch2
  • OR kivio is earlier than 1:1.6.1-2etch2
  • OR koffice-dbg is earlier than 1:1.6.1-2etch2
  • OR koffice-dev is earlier than 1:1.6.1-2etch2
  • OR kugar is earlier than 1:1.6.1-2etch2
  • OR krita is earlier than 1:1.6.1-2etch2
  • OR kplato is earlier than 1:1.6.1-2etch2
  • OR kformula is earlier than 1:1.6.1-2etch2
  • OR kchart is earlier than 1:1.6.1-2etch2
  • OR koffice-libs is earlier than 1:1.6.1-2etch2
  • OR karbon is earlier than 1:1.6.1-2etch2
  • OR koshell is earlier than 1:1.6.1-2etch2
  • OR kspread is earlier than 1:1.6.1-2etch2
  • OR kthesaurus is earlier than 1:1.6.1-2etch2
  • OR kexi is earlier than 1:1.6.1-2etch2
  • OR kword is earlier than 1:1.6.1-2etch2
  • BACK