Security fix for CVE-2017-9433. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2017-3229e88ea3 2017-06-17 19:41:13.852723 --------------------------------------------------------------------------------Name : libmwaw Product : Fedora 26 Version : 0.3.11 Release : 3.fc26 URL : https://sourceforge.net/projects/libmwaw/ Summary : A library for import of many old Mac document formats Description : libmwaw is a library for import of old Mac documents. It supports many kinds of text documents, spreadsheets, databases, vector and bitmap images. Supported are, for example, documents created by BeagleWorks, ClarisWorks, MacPaint, MacWrite or Microsoft Word for Mac. A full list of supported formats is available at . --------------------------------------------------------------------------------Update Information: Security fix for CVE-2017-9433 --------------------------------------------------------------------------------References: [ 1 ] Bug #1461762 - CVE-2017-9433 libmwaw: Out-of-bounds write in the MsWrd1Parser::readFootnoteCorrespondence function https://bugzilla.redhat.com/show_bug.cgi?id=1461762 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade libmwaw' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
libmwaw could be made to crash or run programs as your login if it opened a specially crafted file.. =========================================================================Ubuntu Security Notice USN-3319-1 June 15, 2017 libmwaw vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 17.04 - Ubuntu 16.10 - Ubuntu 16.04 LTS - Ubuntu 14.04 LTS Summary: libmwaw could be made to crash or run programs as your login if it opened a specially crafted file. Software Description: - libmwaw: import library for some old Mac text documents Details: It was discovered that libmwaw incorrectly handled certain malformed document files. If a user or automated system were tricked into opening a specially crafted file, a remote attacker could cause libmwaw to crash, resulting in a denial of service, or possibly execute arbitrary code. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 17.04: libmwaw-0.3-3 0.3.9-1ubuntu0.1 Ubuntu 16.10: libmwaw-0.3-3 0.3.8-2ubuntu0.1 Ubuntu 16.04 LTS: libmwaw-0.3-3 0.3.7-1ubuntu2.1 Ubuntu 14.04 LTS: libmwaw-0.1-1 0.1.11-1ubuntu1.1 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-3319-1 CVE-2017-9433 Package Information: https://launchpad.net/ubuntu/+source/libmwaw/0.3.9-1ubuntu0.1 https://launchpad.net/ubuntu/+source/libmwaw/0.3.8-2ubuntu0.1 https://launchpad.net/ubuntu/+source/libmwaw/0.3.7-1ubuntu2.1 https://launchpad.net/ubuntu/+source/libmwaw/0.1.11-1ubuntu1.1 . Debian Security Advisory DSA-4781-1 outlines a libexample vulnerability that could lead to crashes or unauthorized access via specially crafted files.. libmwaw security, Ubuntu updates, remote code execution, denial ofservice. . Severity: Critical. LinuxSecurity.com Team
It was discovered that a buffer overflow in libmwaw, a library to open old Mac text documents might result in the execution of arbitrary code if a malformed document is opened. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 - ------------------------------------------------------------------------- Debian Security Advisory DSA-3875-1
Get the latest Linux and open source security news straight to your inbox.