Lucene search

K
centosCentOS ProjectCESA-2007:0010-01
HistoryFeb 21, 2007 - 6:28 a.m.

koffice security update

2007-02-2106:28:25
CentOS Project
lists.centos.org
44

6.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

0.141 Low

EPSS

Percentile

95.7%

CentOS Errata and Security Advisory CESA-2007:0010-01

KOffice is a collection of productivity applications for the K Desktop
Environment (KDE) GUI desktop.

An integer overflow bug was found in KOffice’s PPT file processor. An
attacker could create a malicious PPT file that could cause KOffice to
execute arbitrary code if the file was opened by a victim. (CVE-2006-6120)

All users of KOffice are advised to upgrade to these updated packages, which
contains a backported patch to correct this issues.

Merged security bulletin from advisories:
https://lists.centos.org/pipermail/centos-announce/2007-February/075717.html

Affected packages:
koffice
koffice-devel

OSVersionArchitecturePackageVersionFilename
CentOS2i386koffice< 1.1.1-2.3koffice-1.1.1-2.3.i386.rpm
CentOS2i386koffice-devel< 1.1.1-2.3koffice-devel-1.1.1-2.3.i386.rpm

6.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

0.141 Low

EPSS

Percentile

95.7%