_______________________________________________________________________
Package : file
Date : June 5, 2009
Affected: 2009.1
_______________________________________________________________________
Problem Description:
A security vulnerability has been identified and fixed in file:
Heap-based buffer overflow in the cdf_read_sat function in src/cdf.c
in Christos Zoulas file 5.00 allows user-assisted remote attackers
to execute arbitrary code via a crafted compound document file,
as demonstrated by a .msi, .doc, or .mpp file. NOTE: some of these
details are obtained from third party information (CVE-2009-1515).
This update provides file-5.03, which is not vulnerable to this,
and other unspecified issues.
_______________________________________________________________________
References:
http://cve.mitre.org/cgi-bin/cvename.cg ... -2009-1515
_______________________________________________________________________