View Full Version : USN-515-1: t1lib vulnerability

September 19th, 2007, 10:10 PM
Referenced CVEs:

================================================== ========= Ubuntu Security Notice USN-515-1 September 19, 2007 t1lib vulnerability CVE-2007-4033 ================================================== ========= A security issue affects the following Ubuntu releases: Ubuntu 6.06 LTS Ubuntu 6.10 Ubuntu 7.04 This advisory also applies to the corresponding versions of Kubuntu, Edubuntu, and Xubuntu. The problem can be corrected by upgrading your system to the following package versions: Ubuntu 6.06 LTS: libt1-5 5.1.0-2ubuntu0.6.06.1 Ubuntu 6.10: libt1-5 5.1.0-2ubuntu0.6.10.1 Ubuntu 7.04: libt1-5 5.1.0-2ubuntu0.7.04.1 In general, a standard system upgrade is sufficient to affect the necessary changes. Details follow: It was discovered that t1lib does not properly perform bounds checking which can result in a buffer overflow vulnerability. An attacker could send specially crafted input to applications linked against t1lib which could result in a DoS or arbitrary code execution.

More... (http://www.ubuntu.com/usn/usn-515-1)