Acording to the official Koffice release notes, koffice-1.3.4 has an integer overflow vulnerability fix in KWord's PDF import filter which is weak against compiler optimization.
A patch is available at
Please patch the source with it.
Steps to Reproduce:
Looks like the original patch introduced in GLSA 200410-30 and bug 68558 may not be sufficient...
KDE team : We might have to repatch this :/
The reported link doesn't works for me.
This one works
BTW I've noticed that in KDECVS a similar patch was applied also to kpdf, but didn't find any report:
http://lists.kde.org/?l=kde-cvs&m=109895739822113&w=2 >> IT'S WRONG
http://lists.kde.org/?l=kde-cvs&m=109895658125554&w=2 >> IT'S RIGHT BUT APPLIED ON THE UPPER ONE.
Can't find/verify gpg signature. The patch looks good, though.
Arch herds, I have to ask you again: Please mark either one of the above ebuilds stable.
ppc64: Would be nice, if you would use the "second chance". I can dump the old ebuilds in one rush then.
Stable on ppc.
koffice-1.3.3-r2 stable on sparc
1.3.4-r1 stable on alpha.
1.3.4-r1 stable on amd64
1.3.4-r1 stable on ppc64
Looks the same as (still not public) bug 69662 to me. Patches are different, but I would say they patch the same thing. Can someone with access double-confirm this is a different issue ?
Koon: Yes, it is. Koffice is fixed, kdegraphics fixes follow in a few minutes.
Thanks Carsten for clarification.
We'll probably group xpdf 64 bit GLSAs (or update the old xpdf one).
Will be released as a 200410-30 update when bug 69936 will be done.
GLSA 200410-30:02 update out