An untrusted search path vulnerability in Gnumeric might result in the execution of arbitrary code.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200904-03 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: Gnumeric: Untrusted search path Date: April 03, 2009 Bugs: #257012 ID: 200904-03 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= An untrusted search path vulnerability in Gnumeric might result in the execution of arbitrary code. Background ========= The Gnumeric spreadsheet is a versatile application developed as part of the GNOME Office project. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 app-office/gnumeric < 1.8.4-r1 > = 1.8.4-r1 Description ========== James Vega reported an untrusted search path vulnerability in the GObject Python interpreter wrapper in Gnumeric. Impact ===== A local attacker could entice a user to run Gnumeric from a directory containing a specially crafted python module, resulting in the execution of arbitrary code with the privileges of the user running Gnumeric. Workaround ========= Do not run "gnumeric" from untrusted working directories. Resolution ========= All Gnumeric users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =app-office/gnumeric-1.8.4-r1" References ========= [ 1 ] CVE-2009-0318 https://www.cve.org/CVERecord?id=CVE-2009-0318 Availability =========== This GLSA and any updates to it are available for viewing at the GentooSecurity Website: https://security.gentoo.org/glsa/200904-03 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users machines is of utmost importance to us. Any security concerns should be addressed to
Resolves CVE-2009-5983. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2009-1295 2009-02-05 01:17:09 --------------------------------------------------------------------------------Name : gnumeric Product : Fedora 9 Version : 1.8.2 Release : 4.fc9 URL : Summary : Spreadsheet program for GNOME Description : Gnumeric is a spreadsheet program for the GNOME GUI desktop environment. --------------------------------------------------------------------------------ChangeLog: * Fri Jan 30 2009 Huzaifa Sidhpurwala 1:1.8.2-4 - Resolves CVE-2009-5983 - Version Bump --------------------------------------------------------------------------------References: [ 1 ] Bug #481572 - CVE-2009-0318 Gnumeric: untrusted python modules search path https://bugzilla.redhat.com/show_bug.cgi?id=481572 --------------------------------------------------------------------------------This update can be installed with the "yum" update program. Use su -c 'yum update gnumeric' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ Fedora-package-announce mailing list
Thilo Pfennig and Morten Welinder discovered that the XLS spreadsheet handling code in Gnumeric did not correctly calculate needed memory sizes. If a user or automated system were tricked into loading a specially crafted XLS document, a remote attacker could execute arbitrary code with user privileges. . =========================================================== Ubuntu Security Notice USN-604-1 April 22, 2008 gnumeric vulnerability CVE-2008-0668 ========================================================== A security issue affects the following Ubuntu releases: Ubuntu 6.06 LTS Ubuntu 6.10 Ubuntu 7.04 Ubuntu 7.10 This advisory also applies to the corresponding versions of Kubuntu, Edubuntu, and Xubuntu. The problem can be corrected by upgrading your system to the following package versions: Ubuntu 6.06 LTS: gnumeric 1.6.3-0ubuntu4.1 Ubuntu 6.10: gnumeric 1.7.0-1ubuntu4.1 Ubuntu 7.04: gnumeric 1.7.8-0ubuntu1.1 Ubuntu 7.10: gnumeric 1.7.11-1ubuntu3.1 After a standard system upgrade you need to restart gnumeric to effect the necessary changes. Details follow: Thilo Pfennig and Morten Welinder discovered that the XLS spreadsheet handling code in Gnumeric did not correctly calculate needed memory sizes. If a user or automated system were tricked into loading a specially crafted XLS document, a remote attacker could execute arbitrary code with user privileges. Updated packages for Ubuntu 6.06 LTS: Source archives: Size/MD5: 39323 42574f5797fcb226ef7528181035d31c Size/MD5: 1392 b1628c2e7b4d4a78818f09de3e596cda Size/MD5: 16479052 da792f23bf26a69788736088e69fc7c0 Architecture independent packages: Size/MD5: 258934 1c30004cd9d4443f48fb74e0357dbb26 Size/MD5: 4171512 587217e92ec63e28c30c90951bb499d4 amd64 architecture (Athlon64, Opteron, EM64T Xeon): Size/MD5: 2022790 29be161b0419af30e692b232ad012179 Size/MD5: 156402 9e44cd40784f0a4c9ab54d53731689eb Size/MD5: 2190380 307ed2f6290371777dd0bd8390efb280 i386 architecture (x86 compatible Intel/AMD): Size/MD5: 1839904 31f48a91d2feda9ffb730f0ed5c605d2 Size/MD5: 150402 bbd8fae8e2917028fde1c2fdc9868bdf Size/MD5: 2004104 e219d6ab8ffe2507535a3d0d92fc87b9 powerpc architecture (Apple Macintosh G3/G4/G5): Size/MD5: 2023376 bf62ee21a1b224774d0d5ab086ddbb38 Size/MD5: 156886 ef7c27b3560402fdd6408e083c4229a1 Size/MD5: 2195736 f13fb41011cbaaef437ff3086e8ba50a sparc architecture (Sun SPARC/UltraSPARC): Size/MD5: 1949834 c801e237cb504629685f1885fecaca2b Size/MD5: 152654 a08a044cc0b3aa7546eef87378974db1 Size/MD5: 2114764 2a34e8b43ec31a8e78be3ec52492dd2e Updated packages for Ubuntu 6.10: Source archives: Size/MD5: 45261 7565d8605bca038543084fcbc78d4845 Size/MD5: 1378 366052e7cdf751cbea1f1d894077cc30 Size/MD5: 16535049 9943fe7fe942ced6187d73fc334e6707 Architecture independent packages: Size/MD5: 366210 ccb44a14e76e4ef57312a71f2bc6e35f Size/MD5: 4184614 fa368b34254b4ee2618bf159a463e53d amd64 architecture (Athlon64, Opteron, EM64T Xeon): Size/MD5: 2087748 390a95976f17ab6a7a65271836d8a261 Size/MD5: 170090 3268feb35204eca92b3b908f468a0f67 Size/MD5: 2259060 ab4d6e1a0815f4f20fde944954f06943 i386 architecture (x86 compatible Intel/AMD): Size/MD5: 1958608 a821c922acba32be87cbd00e4f09d3af Size/MD5: 165110 f2abe52d16e3b770097b41a5ec086537 Size/MD5: 2132484 8862169b3ca2058b44d58f133e7f0c8b powerpc architecture (Apple Macintosh G3/G4/G5): Size/MD5: 2095692 e20b237a7667b8fe1f26a18c74972683 Size/MD5: 170628 8c15273771f1b4e06516b1022633347d Size/MD5: 2269756ca07ce5b14cbc24d30574aa12d442213 sparc architecture (Sun SPARC/UltraSPARC): Size/MD5: 2010592 d49c51704da28e96c0d7c8d230b7fceb Size/MD5: 165998 9af74233f30ab1b68dbd14ee1fd900a9 Size/MD5: 2184538 f2b4e9ce72bcd381afb90614aa62a7da Updated packages for Ubuntu 7.04: Source archives: Size/MD5: 48102 4cb4b66876b137433661b6446c363f36 Size/MD5: 1439 4a43bc0852c9c88d055eaf87ff879bd7 Size/MD5: 17058762 b03c5ba327fad7dc331e113b7f531210 Architecture independent packages: Size/MD5: 265514 47a4359a683a02445fea4d4b25a38d3c Size/MD5: 4143238 4cd31e5683e5d46d33655722c0a306ef amd64 architecture (Athlon64, Opteron, EM64T Xeon): Size/MD5: 2122024 f5ee64a51c1cbc071f6565d02d304eac Size/MD5: 130022 e51a82c0d7f8cab43f7dc105da3a5685 Size/MD5: 2302878 e1955434fa5f79d5bbe6db8ca4fc9882 i386 architecture (x86 compatible Intel/AMD): Size/MD5: 1982206 72af664845f20250cfe6ce75e1b95764 Size/MD5: 125050 3e7e0a9c2215e3844a4551e6a3507411 Size/MD5: 2164976 475764927dced5df4b4bf367db41fc26 powerpc architecture (Apple Macintosh G3/G4/G5): Size/MD5: 2260072 6defff3e93bd5aad82347c503ca51683 Size/MD5: 135964 4f5d5cd7e11c0a4f902b6515da408580 Size/MD5: 2442084 bfda15f48688cc98413a562a29bbe2c0 sparc architecture (Sun SPARC/UltraSPARC): Size/MD5: 2044240 a506f3573c8145ddd66e61dc2ddb0646 Size/MD5: 125784 f6e1d5d973985dea00697123d4c30a51 Size/MD5: 2224148 59d58a3a54e66ad14439d3fa63d4bc80 Updated packages for Ubuntu 7.10: Source archives: Size/MD5: 47530 aa0e6a89376cbd357399943ff92252e1 Size/MD5: 1375 c1884a9ba0a346d3ed8563f7845ab0f0 Size/MD5: 17274168 8d07bbd5b57f55bbd26e0815d4146f9e Architecture independent packages: Size/MD5: 264998 53c0609a802420302188612056afbad1 Size/MD5: 4155974 4760c4d176646988a566c4ec957a1e03 amd64 architecture (Athlon64, Opteron, EM64T Xeon): Size/MD5: 2145298 bfb0f86aa2dd8a223e3e3760a9a0a059 Size/MD5: 142752 86394e3f002cb064e81a567e715c989c Size/MD5: 2331142 4b26c626508ad62d537b7d960ffefc4b i386 architecture (x86 compatible Intel/AMD): Size/MD5: 2005598 b114318f75a12e4374d15b3fcc9231e1 Size/MD5: 137866 0a1204f80dc3f54c5e375504764eae1f Size/MD5: 2189096 1fd2ddae9a5e0015684e47c182bdea1f powerpc architecture (Apple Macintosh G3/G4/G5): Size/MD5: 2281254 b1fb989c0f54c1377ac3691eba0d0c56 Size/MD5: 148522 21432f8c173c2e1777cfc36fa033a3ca Size/MD5: 2468958 4a1261f085e0d779f66ece69e8dac2b0 sparc architecture (Sun SPARC/UltraSPARC): Size/MD5: 2067614 86b25a9c7f7b28f1eeb829cd8aee34c4 Size/MD5: 138404 b38d4b16c9ce1a3c70dcad82f059d578 Size/MD5: 2252586 9b11db6d2a2e0cc7fb53a4497390c774 . A vulnerability in Gnumeric may enable remote code execution through specially designed XLS files. System updates are necessary to mitigate risks.. Gnumeric Security, Ubuntu Advisory, Memory Handling Issue. . Severity: Important. LinuxSecurity.com Team
Thilo Pfennig and Morten Welinder discovered several integer overflow weaknesses in Gnumeric, a GNOME spreadsheet application. These vulnerabilities could result in the execution of arbitrary code through the opening of a maliciously crafted Excel spreadsheet.. - ------------------------------------------------------------------------Debian Security Advisory DSA-1546-1
A potential security problem has been fixed in the gnumeric spreadsheet package. . Red Hat, Inc. Security Advisory Package gnumeric Synopsis Potential security problem in gnumeric 0.23 Advisory ID RHSA-1999:023-01 Issue Date 1999-07-23 Keywords gnumeric security 1. Topic: A potential security problem has been fixed in the gnumeric spreadsheet package. 2. Bug IDs fixed: 3. Relevant releases/architectures: Red Hat Linux 6.0, all architectures 4. Obsoleted by: None 5. Conflicts with: None 6. RPMs required: Intel: gnumeric- 0.27-1.i386.rpm Alpha: gnumeric-0.27-1.alpha.rpm SPARC: gnumeric-0.27-1.sparc.rpm Source: gnumeric- 0.27-1.src.rpm 7. Problem description: At the request of the gnumeric maintainer a new version is being released by Red Hat which addresses potential security issues with the version of gnumeric shipped in Red Hat Linux 6.0. 8. Solution: Upgrade to the latest version listed above. 9. Verification: MD5 sum Package Name ------------------------------------------------------------------------- 41d67505f1c53ce16ea66cec874deb87 gnumeric-0.27-1.i386.rpm 89451cf299e475197350ef0367edda63 gnumeric-0.27-1.alpha.rpm c35d7f9a29fd9421ef4d5b1ac44d6b8e gnumeric-0.27-1.sparc.rpm b28c5742c32c3d69b8e6713bb7c6f789 gnumeric-0.27-1.src.rpm These packages are also PGP signed by Red Hat Inc. for security. Our key is available at: You can verify each package with the following command: rpm --checksig If you only wish to verify that each package has not been corrupted o tampered with, examine only the md5sum with the following command: rpm --checksig --nopgp 10. References: . The Gnumeric spreadsheet tool has been patched due to a critical security vulnerability. Make sure your system is updated to enhance protection.. Gnumeric Security, Software Update, Red Hat Advisory. . Severity: Critical. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.