Debian Security Advisory

DSA-3158-1 unrtf -- security update

Date Reported:
09 Feb 2015
Affected Packages:
unrtf
Vulnerable:
Yes
Security database references:
In the Debian bugtracking system: Bug 772811.
In Mitre's CVE dictionary: CVE-2014-9274, CVE-2014-9275.
More information:

Michal Zalewski and Hanno Boeck discovered several vulnerabilities in unrtf, a RTF to other formats converter, leading to a denial of service (application crash) or, potentially, the execution of arbitrary code.

For the stable distribution (wheezy), these problems have been fixed in version 0.21.5-3~deb7u1. This update is based on a new upstream version of unrtf including additional bug fixes, new features and incompatible changes (especially PostScript support is dropped).

For the upcoming stable distribution (jessie) and the unstable distribution (sid), these problems have been fixed in version 0.21.5-2.

We recommend that you upgrade your unrtf packages.