[gnumeric] [CVE-2008-0668] possible execution of arbitrary code via a crafted XLS file

Bug #198662 reported by disabled.user
256
Affects Status Importance Assigned to Milestone
gnumeric (Ubuntu)
Fix Released
Low
Kees Cook

Bug Description

Binary package hint: gnumeric

References:
MDVSA-2008:056 (http://www.mandriva.com/en/security/advisories?name=MDVSA-2008:056)

Quoting:
"A vulnerability was found in the excel_read_HLINK function in the
Microsoft Excel plugin in Gnumeric prior to version 1.8.1 that would
allow for the execution of arbitrary code via a crafted XLS file
containing XLS HLINK opcodes."

CVE References

Revision history for this message
Kees Cook (kees) wrote :

This problem has been addressed with the following USN: http://www.ubuntu.com/usn/usn-604-1

Changed in gnumeric:
assignee: nobody → keescook
importance: Undecided → Low
status: New → Fix Released
To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.