ArchLinux: 201412-20: unrtf: arbitrary code execution
Summary
- CVE-2014-9274 (arbitrary code execution)
A flaw allows remote attackers to cause a denial of service (crash) and
possibly execute arbitrary code as demonstrated by a file containing the
string "{\cb-999999999".
- CVE-2014-9275 (arbitrary code execution)
A flaw allows remote attackers to cause a denial of service
(out-of-bounds memory access and crash) and possibly execute arbitrary
code via a crafted RTF file.
Resolution
Upgrade to 0.21.7-1.
# pacman -Syu "unrtf>=0.21.7-1"
The problems have been fixed upstream in version 0.21.7.
References
https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2014-9274 https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2014-9275 https://bugzilla.redhat.com/show_bug.cgi?id=1170233 https://seclists.org/oss-sec/2014/q4/904 https://bugs.archlinux.org/task/43131
Workaround
None.