This advisory also applies to the corresponding versions of Kubuntu, Edubuntu, and Xubuntu.
Jan Oravec discovered that Tomboy did not properly setup the LD_LIBRARY_PATH environment variable. A local attacker could exploit this to execute arbitrary code as the user invoking the program.
Solution: The problem can be corrected by upgrading your system to the following package versions:
Ubuntu 6.06 LTS: tomboy 0.3.5-1ubuntu3.1
Ubuntu 6.10: tomboy 0.4.1-0ubuntu3.1
Ubuntu 7.04: tomboy 0.6.3-0ubuntu1.1
Ubuntu 7.10: tomboy 0.8.0-1ubuntu0.1
After a standard system upgrade you need to restart Tomboy to effect the necessary changes.