Accepted koffice 1:1.4.2-3ubuntu3 (source)
Jonathan Riddell
jriddell at ubuntu.com
Mon Dec 12 17:50:16 GMT 2005
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
Format: 1.7
Date: Mon, 12 Dec 2005 17:42:39 +0000
Source: koffice
Binary: koffice-data kspread kivio koffice kword krita kugar kchart karbon kpresenter koffice-dev koffice-doc-html kformula koffice-libs kivio-data koshell
Architecture: source
Version: 1:1.4.2-3ubuntu3
Distribution: dapper
Urgency: low
Maintainer: Debian Qt/KDE Maintainers <debian-qt-kde at lists.debian.org>
Changed-By: Jonathan Riddell <jriddell at ubuntu.com>
Description:
karbon - a vector graphics application for the KDE Office Suite
kchart - a chart drawing program for the KDE Office Suite
kformula - a formula editor for the KDE Office Suite
kivio - a flowcharting program for the KDE Office Suite
kivio-data - data files for Kivio flowcharting program
koffice - KDE Office Suite
koffice-data - common shared data for the KDE Office Suite
koffice-dev - common libraries for KOffice (development files)
koffice-doc-html - KDE Office Suite documentation in HTML format
koffice-libs - common libraries and binaries for the KDE Office Suite
koshell - the KDE Office Suite workspace
kpresenter - a presentation program for the KDE Office Suite
krita - a pixel-based image manipulation program for the KDE Office Suite
kspread - a spreadsheet for the KDE Office Suite
kugar - a business report maker for the KDE Office Suite
kword - a word processor for the KDE Office Suite
Changes:
koffice (1:1.4.2-3ubuntu3) dapper; urgency=low
.
* SECURITY UPDATE: Multiple integer/buffer overflows.
* Update kubuntu_02_xpdf_vulnerability.diff
* xpdf/Stream.cc, DCTStream::readBaselineSOF(),
DCTStream::readProgressiveSOF(), DCTStream::readScanInfo():
- Check numComps for invalid values.
- http://www.idefense.com/application/poi/display?id=342&type=vulnerabilities
- CVE-2005-3191
* xpdf/Stream.cc, StreamPredictor::StreamPredictor():
- Check rowBytes for invalid values.
- http://www.idefense.com/application/poi/display?id=344&type=vulnerabilities
- CVE-2005-3192
* xpdf sources do not contain JPXStream.cc, and are thus
not vulnerable against CVE-2005-3193
Files:
39843be860f340c0fbf13f803fd08c16 1100 kde optional koffice_1.4.2-3ubuntu3.dsc
072f5babf0b83543f1748e84dbed15e6 3187631 kde optional koffice_1.4.2-3ubuntu3.diff.gz
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.2 (GNU/Linux)
iD8DBQFDnbcYpQbm1N1NUIgRAsxFAJ40epJEHGplkgRXLlt4XM3qUPvu2gCcDExF
jhmqQOk/Uoghg+sP1xZ4Fko=
=t/72
-----END PGP SIGNATURE-----
Accepted:
koffice_1.4.2-3ubuntu3.diff.gz
to pool/main/k/koffice/koffice_1.4.2-3ubuntu3.diff.gz
koffice_1.4.2-3ubuntu3.dsc
to pool/main/k/koffice/koffice_1.4.2-3ubuntu3.dsc
More information about the dapper-changes
mailing list