Fedora Core 5 Update:

Posted by Benjamin D. Thomas   
Fedora A heap overflow flaw was found in the RTF import filer. An attacker could create a carefully crafted RTF file that could cause to crash or possibly execute arbitrary code if the file was opened by a victim. All users of are advised to upgrade to these updated packages, which contain a backported fix to correct this issue.
Fedora Update Notification

Product     : Fedora Core 5
Name        :
Version     : 2.0.2
Release     : 5.22.2
Summary     : comprehensive office suite.
Description : is an Open Source, community-developed, multi-platform
office productivity suite.  It includes the key desktop applications,
such as a word processor, spreadsheet, presentation manager, formula
editor and drawing program, with a user interface and feature set
similar to other office suites.  Sophisticated and flexible, also works transparently with a variety of file
formats, including Microsoft Office.

Usage: Simply type "ooffice" to run or select the
requested component (Writer, Calc, Draw, Impress, etc.) from your
desktop menu. On first start a few files will be installed in the
user's home, if necessary.

The team hopes you enjoy working with!

Update Information:

A heap overflow flaw was found in the RTF import filer. An
attacker could create a carefully crafted RTF file that
could cause to crash or possibly execute
arbitrary code if the file was opened by a victim.

All users of are advised to upgrade to these
updated packages, which contain a backported fix to correct
this issue. 
* Fri Jun  1 2007 Caolan McNamara  - 1:2.0.2-5.22
- Resolves: CVE-2007-0245 ooo#77214 rtf prtdata
* Tue Feb 20 2007 Caolan McNamara  - 1:2.0.2-5.21
- Resolves: CVE-2007-0239 rhbz#228008 shell escape
- Resolves: CVE-2007-0238 rhbz#226966 buffer overflows
* Mon Dec  4 2006 Caolan McNamara  - 1:2.0.2-5.20
- Resolves: rhbz#217347
* Wed Sep 27 2006 Caolan McNamara  - 1:2.0.2-5.19
- add for rh#206177#
- add for rh#206051#
* Tue Sep  5 2006 Caolan McNamara  - 1:2.0.2-5.18
- add
- add
* Fri Jul  7 2006 Caolan McNamara  - 1:2.0.2-5.17
- rh#197618# add
- add to make 
  ~/.recently-used safe
- add
- rh#198603# gcc ate my office suite, add
- gcc#28370# I'm suspicious of these statics lately
* Fri Jun 30 2006 Caolan McNamara  - 1:2.0.2-5.16
- CVE-2006-2198 macro security
- CVE-2006-2199 java applets
- CVE-2006-3117 corrupt file format
- rh#195637# add
- add to
  fix visibility problem
* Thu Jun  8 2006 Caolan McNamara  - 1:2.0.2-5.13
- rh#193918# add

This update can be downloaded from:

This update can be installed with the 'yum' update program.  Use 'yum update
package-name' at the command line.  For more information, refer to 'Managing
Software with yum,' available at

Fedora-package-announce mailing list
