CVE-2009-2950

Publication date 16 February 2010

Last updated 24 July 2024


Ubuntu priority

Heap-based buffer overflow in the GIFLZWDecompressor::GIFLZWDecompressor function in filter.vcl/lgif/decode.cxx in OpenOffice.org (OOo) before 3.2 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted GIF file, related to LZW decompression.

Status

Package Ubuntu Release Status
openoffice.org 9.10 karmic
Fixed 1:3.1.1-5ubuntu1.1
9.04 jaunty
Fixed 1:3.0.1-9ubuntu3.2
8.10 intrepid
Fixed 1:2.4.1-11ubuntu2.3
8.04 LTS hardy
Fixed 1:2.4.1-1ubuntu2.3
6.06 LTS dapper Ignored end of life

References

Related Ubuntu Security Notices (USN)

    • USN-903-1
    • OpenOffice.org vulnerabilities
    • 24 February 2010

Other references