Updated libwpd packages to correct a security issue are now available for
CentOS Linux 5.
This update has been rated as having important security impact by the Red
Hat Security Response Team.
libwpd is a library for reading and converting Word Perfect documents.
iDefense reported several overflow bugs in libwpd. An attacker could
create a carefully crafted Word Perfect file that could cause an
application linked with libwpd, such as OpenOffice, to crash or possibly
execute arbitrary code if the file was opened by a victim. (CVE-2007-0002)
All users are advised to upgrade to these updated packages, which contain a
backported fix for this issue.
CentOS would like to thank Fridrich Strba for alerting us to these issues
and providing a patch.