Title : Ubuntu Security Update Fixes Cairo "read_png()" Integer Overflow Issue VUPEN ID : VUPEN/ADV-2007-4149 CVE ID : CVE-2007-5503
Rated as : Moderate Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2007-12-11
Technical Description
A vulnerability has been identified in Ubuntu, which could be exploited by attackers to cause a denial of service or execute arbitrary code. This issue is caused by an error in Cairo. For additional information, see : VUPEN/ADV-2007-4045
Ubuntu 6.06 LTS - Upgrade to libcairo2 version 1.0.4-0ubuntu1.2
Ubuntu 6.10 - Upgrade to libcairo2 version 1.2.4-1ubuntu2.2
Ubuntu 7.04 - Upgrade to libcairo2 version 1.4.2-0ubuntu1.3
Ubuntu 7.10 - Upgrade to libcairo2 version 1.4.10-1ubuntu4.4 References