Vendor notifies:
A security vulnerability with the way OpenOffice 2.x process WMF files may allow a remote unprivileged user who provides a StarOffice/StarSuite document that is opened by a local user to execute arbitrary commands on the system with the privileges of the user running StarOffice/StarSuite. No working exploit is known right now.
A security vulnerability with the way OpenOffice 2.x process EMF files may allow a remote unprivileged user who provides a StarOffice/StarSuite document that is opened by a local user to execute arbitrary commands on the system with the privileges of the user running StarOffice/StarSuite. No working exploit is known right now.
ChangeLog for CUPS 1.3.10 says:
SECURITY: The PNG image reading code did not validate the image size properly, leading to a potential buffer overflow (STR #2974)
Vendor reports:
Samba 3.0.29 to 3.2.4 can potentially leak arbitrary memory contents to malicious clients
Tobias Klein from TrapKit notifies:
The VLC media player contains a stack overflow vulnerability while parsing malformed TiVo ty media files. The vulnerability can be trivially exploited by a (remote) attacker to execute arbitrary code in the context of VLC media player.
Entry for CVE-2008-4686 says:
Multiple integer overflows in ty.c in the TY demux plugin (aka the TiVo demuxer) in VideoLAN VLC media player, probably 0.9.4, allow remote attackers to have an unknown impact via a crafted .ty file, a different vulnerability than CVE-2008-4654.
Description for CVE-2008-3432 says:
Heap-based buffer overflow in the mch_expand_wildcards function in os_unix.c in Vim 6.2 and 6.3 allows user-assisted attackers to execute arbitrary code via shell metacharacters in filenames, as demonstrated by the netrw.v3 test case.
Jan Lieskovsky reports:
perl-File-Path rmtree race condition (CVE-2005-0448 was assigned to address this)
This vulnerability was fixed in 5.8.4-7 but re-introduced in 5.8.8-1. It's also present in File::Path 2.xx, up to and including 2.07 which has only a partial fix.
Stephan Bosch, maintainer of dovecot-managesieve, reports:
…clever virtual users that know the directory structure of the server can read and edit script files of other virtual users with the same system uid.
Niko Tyni from Debian reports:
CVE-2005-0448 (File::Path::rmtree races) has resurfaced and is present in all of etch, lenny, and sid.
To be precise, CVE-2005-0448 was about two bugs (#286922 and #286905). Both of those apply to the etch package (perl-5.8.8), while only #286905 applies to the lenny/sid package (perl-5.10.0).