RHEL 5 : libwpd (RHSA-2007:0055)
High Nessus Plugin ID 25312
SynopsisThe remote Red Hat host is missing one or more security updates.
DescriptionUpdated libwpd packages to correct a security issue are now available for Red Hat Enterprise Linux 5.
This update has been rated as having important security impact by the Red Hat Security Response Team.
libwpd is a library for reading and converting Word Perfect documents.
iDefense reported several overflow bugs in libwpd. An attacker could create a carefully crafted Word Perfect file that could cause an application linked with libwpd, such as OpenOffice, to crash or possibly execute arbitrary code if the file was opened by a victim.
All users are advised to upgrade to these updated packages, which contain a backported fix for this issue.
Red Hat would like to thank Fridrich Strba for alerting us to these issues and providing a patch.
SolutionUpdate the affected libwpd, libwpd-devel and / or libwpd-tools packages.