Linux Compatible
  • News
    • Channels
    • Archive
    • Search
    • Submit
  • Articles
    • Categories
  • Knowledgebase
  • Compatibility
    • Search
  • Links
  • Forums
  • Twitter
Advertisement

Latest News
[ Windows | Linux | Apple ]

· Daily Reviews Summary 05/25/12
· CompatDB Updates 05/25/12
· Rumor: Microsoft Office coming to iPad, Android in November
· Microsoft clarifies Ballmer's claims of massive Windows 8 adoption
· DSA 2480-1: request-tracker3.8 security update
· CentOS 6 NTP Server
· Daily Reviews Summary 05/24/12
· Bayan Audio - Bayan 7 iPod Speaker Dock Review
· Installing Nginx With PHP5 (And PHP-FPM) And MySQL Support (LEMP) On Ubuntu 12.04 LTS
· Ubuntu 12.04 + Nvidia - Heavy CPU usage

Upcoming News
· Thermaltake ToughPower Grand 850W Power Supply Review @ Rbmods
· Cooler Master Silent Pro Gold 1200-watt Power Supply Review
· Wine release 1.5.5
· OC3D: BitFenix Prodigy Review
· [Tech ARP] The New x264 HD Benchmark 5.0 Is Here!
· re: Diablo III Reviewed: Blizzard's Brilliant, Blundering Wreck
· Corsair Vengeance C70 Case Review @ Hardware Secrets
· Diablo III Reviewed: Blizzard's Brilliant, Blundering Wreck
· Samsung Green DDR3 8GB 1600mhz 30nm Memory review
· Withings Wi-Fi Body Scale Review @ TestFreaks

Linux Compatibility
· Canon Canoscan N650U
· TB-5300 Slimline Design Tablet
· HANDYCAM DCR-HC17E
· Linksys Wireless-G WPC54G PC-Card
· XPS L502X
· Slim Portable DVD Writer GP10
· AverTV Volar Green HD
· Dell Latitude E6420
· Canon CanoScan FB 636U
· Logitech QuickCam Pro 4000

New Forum Topics
· USB Not detected on any PC
by: AntNik45
on: 2012-05-09 18:37
0 replies, 0 views

· RESIDENT EVIL 2 for PC
by: elyp00
on: 2012-05-04 07:55
0 replies, 0 views

· Need to know if those graphic cards works well on Ubuntu
by: Dechiqtor
on: 2012-04-19 23:04
0 replies, 0 views

· Obtaining IE8
by: packman
on: 2012-04-14 19:46
0 replies, 0 views

· A few problems running Warcraft II Battle.net Edition on Vista
by: Lord Claremorris
on: 2012-04-08 16:15
0 replies, 0 views

News Channels
· Drivers
· Guides
· Reviews
· Security
· Software
· Press Release
· Updates
· Interviews
· Linux
· General
· Debian
· Red Hat
· Slackware
· Gentoo
· Mandriva
· White Box
· SUSE
· GNOME
· KDE
· CentOS
· Ubuntu
· MEPIS
· Android

What's New
Login to see an overview of all news stories since your last visit.

Welcome to our website

To take full advantage of all features you need to login or register. Registration is completely free and takes only a few seconds.

Linux Compatible » News » April 2008 » DSA 1546-1: New gnumeric packages fix arbitrary code execution

DSA 1546-1: New gnumeric packages fix arbitrary code execution

Posted by Bob on: 04/10/2008 11:05 PM [ Print | 0 comment(s) ]

The Debian Security Team published a new security update for Debian GNU/Linux. Here the announcement:




-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

- ------------------------------------------------------------------------
Debian Security Advisory DSA-1546-1 security@debian.org
http://www.debian.org/security/ Devin Carraway
April 10, 2008 http://www.debian.org/security/faq
- ------------------------------------------------------------------------

Package : gnumeric
Vulnerability : integer overflow
Problem type : local (remote)
Debian-specific: no
CVE Id(s) : CVE-2008-0668

Thilo Pfennig and Morten Welinder discovered several integer overflow
weaknesses in Gnumeric, a GNOME spreadsheet application. These
vulnerabilities could result in the execution of arbitrary code
through the opening of a maliciously crafted Excel spreadsheet.

For the stable distribution (etch), these problems have been fixed in
version 1.6.3-5+etch1.

For the unstable (sid) distribution, these problems were fixed in
version 1.8.1-1.

We recommend that you upgrade your gnumeric packages.

Upgrade instructions
- --------------------

wget url
will fetch the file for you
dpkg -i file.deb
will install the referenced file.

If you are using the apt-get package manager, use the line for
sources.list as given below:

apt-get update
will update the internal database
apt-get upgrade
will install corrected packages

You may use an automated update by adding the resources from the
footer to the proper configuration.


Debian 4.0 (stable)
- -------------------

Stable updates are available for alpha, amd64, arm, hppa, i386, ia64, mips, mipsel, powerpc, s390 and sparc.

Source archives:

http://security.debian.org/pool/updates/main/g/gnumeric/gnumeric_1.6.3-5.1+etch1.dsc
Size/MD5 checksum: 1332 bf302ccff8f47985439966110044db14
http://security.debian.org/pool/updates/main/g/gnumeric/gnumeric_1.6.3.orig.tar.gz
Size/MD5 checksum: 16479052 da792f23bf26a69788736088e69fc7c0
http://security.debian.org/pool/updates/main/g/gnumeric/gnumeric_1.6.3-5.1+etch1.diff.gz
Size/MD5 checksum: 358014 8daad80708cbf16cf362475437304e96

Architecture independent packages:

http://security.debian.org/pool/updates/main/g/gnumeric/gnumeric-common_1.6.3-5.1+etch1_all.deb
Size/MD5 checksum: 5272974 82f8f43a0c2a8a6d9803e7cdfa0326dd
http://security.debian.org/pool/updates/main/g/gnumeric/gnumeric-doc_1.6.3-5.1+etch1_all.deb
Size/MD5 checksum: 4171320 f42bd6770c540f759763a849d7dea505

alpha architecture (DEC Alpha)

http://security.debian.org/pool/updates/main/g/gnumeric/gnumeric-plugins-extra_1.6.3-5.1+etch1_alpha.deb
Size/MD5 checksum: 158390 458b52bbf3d015c432da2b889d7c3eca
http://security.debian.org/pool/updates/main/g/gnumeric/gnumeric_1.6.3-5.1+etch1_alpha.deb
Size/MD5 checksum: 2351352 7b078d3fcf9a27b75012bec809759981

amd64 architecture (AMD x86_64 (AMD64))

http://security.debian.org/pool/updates/main/g/gnumeric/gnumeric-plugins-extra_1.6.3-5.1+etch1_amd64.deb
Size/MD5 checksum: 156908 8860c1fd0ff35c0a1eda83758fa69457
http://security.debian.org/pool/updates/main/g/gnumeric/gnumeric_1.6.3-5.1+etch1_amd64.deb
Size/MD5 checksum: 2202134 1d74f4a0c7ede26d7911743793f1c548

arm architecture (ARM)

http://security.debian.org/pool/updates/main/g/gnumeric/gnumeric-plugins-extra_1.6.3-5.1+etch1_arm.deb
Size/MD5 checksum: 151102 41063103b8246a7bcc39db1b54a6b065
http://security.debian.org/pool/updates/main/g/gnumeric/gnumeric_1.6.3-5.1+etch1_arm.deb
Size/MD5 checksum: 2018806 a486eca4fd7b88eb39829eed0743c22d

hppa architecture (HP PA RISC)

http://security.debian.org/pool/updates/main/g/gnumeric/gnumeric-plugins-extra_1.6.3-5.1+etch1_hppa.deb
Size/MD5 checksum: 161850 fc036ed19c3b161c0d8b06b15e47c9d6
http://security.debian.org/pool/updates/main/g/gnumeric/gnumeric_1.6.3-5.1+etch1_hppa.deb
Size/MD5 checksum: 2418880 0f41e79ac16f966b9bb481ea414a0662

i386 architecture (Intel ia32)

http://security.debian.org/pool/updates/main/g/gnumeric/gnumeric_1.6.3-5.1+etch1_i386.deb
Size/MD5 checksum: 2097038 ce792c3212eb3b912abe060b6438e4fc
http://security.debian.org/pool/updates/main/g/gnumeric/gnumeric-plugins-extra_1.6.3-5.1+etch1_i386.deb
Size/MD5 checksum: 152302 df7cdbb758709551116b0b7a1af8757b

ia64 architecture (Intel ia64)

http://security.debian.org/pool/updates/main/g/gnumeric/gnumeric_1.6.3-5.1+etch1_ia64.deb
Size/MD5 checksum: 2977964 b410a9d5a465433dc6963c9fdf6e7954
http://security.debian.org/pool/updates/main/g/gnumeric/gnumeric-plugins-extra_1.6.3-5.1+etch1_ia64.deb
Size/MD5 checksum: 173702 c34442685a8732e55136152c4da8ac90

mips architecture (MIPS (Big Endian))

http://security.debian.org/pool/updates/main/g/gnumeric/gnumeric-plugins-extra_1.6.3-5.1+etch1_mips.deb
Size/MD5 checksum: 150700 31f9785f14f2b54963ea6992e201ce6d
http://security.debian.org/pool/updates/main/g/gnumeric/gnumeric_1.6.3-5.1+etch1_mips.deb
Size/MD5 checksum: 2141368 62a06754168c251e1c31f4141e584b1b

mipsel architecture (MIPS (Little Endian))

http://security.debian.org/pool/updates/main/g/gnumeric/gnumeric_1.6.3-5.1+etch1_mipsel.deb
Size/MD5 checksum: 2129564 49b647ce4185516cad2dd87f016a6624
http://security.debian.org/pool/updates/main/g/gnumeric/gnumeric-plugins-extra_1.6.3-5.1+etch1_mipsel.deb
Size/MD5 checksum: 149690 fc516ba96c1b24dd7e12b94cb5a64538

powerpc architecture (PowerPC)

http://security.debian.org/pool/updates/main/g/gnumeric/gnumeric_1.6.3-5.1+etch1_powerpc.deb
Size/MD5 checksum: 2209046 c92394d958dbe9a8783cdd4dbab07b14
http://security.debian.org/pool/updates/main/g/gnumeric/gnumeric-plugins-extra_1.6.3-5.1+etch1_powerpc.deb
Size/MD5 checksum: 157418 56b47e7648eeefa105838e9c2239099a

s390 architecture (IBM S/390)

http://security.debian.org/pool/updates/main/g/gnumeric/gnumeric-plugins-extra_1.6.3-5.1+etch1_s390.deb
Size/MD5 checksum: 158596 cbb78e0a514eac16f14184936215b3ba
http://security.debian.org/pool/updates/main/g/gnumeric/gnumeric_1.6.3-5.1+etch1_s390.deb
Size/MD5 checksum: 2264012 d3e7a47436ebc4e6e272d4dedeffbe90

sparc architecture (Sun SPARC/UltraSPARC)

http://security.debian.org/pool/updates/main/g/gnumeric/gnumeric-plugins-extra_1.6.3-5.1+etch1_sparc.deb
Size/MD5 checksum: 152794 d77d8a2e12e862cf1be3d8018eb2fcd7
http://security.debian.org/pool/updates/main/g/gnumeric/gnumeric_1.6.3-5.1+etch1_sparc.deb
Size/MD5 checksum: 2125056 4f1771e3f2f19b45ac862e6ab48d7974


These files will probably be moved into the stable distribution on
its next update.

- ---------------------------------------------------------------------------------
For apt-get: deb http://security.debian.org/ stable/updates main
For dpkg-ftp: ftp://security.debian.org/debian-security dists/stable/updates/main
Mailing list: debian-security-announce@lists.debian.org
Package info: `apt-cache show lt;pkggt;' and http://packages.debian.org/lt;pkggt;

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.6 (GNU/Linux)

iD8DBQFH/ooKXm3vHE4uyloRAoz8AKCkcSra7966aft7NSagAEs+YSvxiACg4ZEi
xG7Fgnl8LXBOli1s//O/hmw=
=ITdl
-----END PGP SIGNATURE-----


Bookmark and Share

« DSA 1545-1: New rsync packages fix arbitrary code execution · McAfee Virus SuperDAT Definitions Update 5271 »

Linux Compatible » News » April 2008 » DSA 1546-1: New gnumeric packages fix arbitrary code execution
All products mentioned are registered trademarks or trademarks of their respective owners.
© 2002-2011 Esselbach Internet Solutions - All Rights Reserved. Terms and privacy policy
Powered by Contentteller® Business Edition