Alerts This Week
Warning Icon 1 681
Alerts This Week
Warning Icon 1 681

Debian: DSA-1793-1 Critical: Kdegraphics Denial Of Service Threats

debian
Calendar Grey May 6, 2009
Debian Logo
Enhance kdegraphics in Debian to remedy various security vulnerabilities, encompassing potential denial of service and execution risks.
kpdf, a Portable Document Format (PDF) viewer for KDE, is based on the xpdf program and thus suffers from similar flaws to those described in DSA-1790

Summary

The Common Vulnerabilities and Exposures project identifies the
following problems:

CVE-2009-0146

Multiple buffer overflows in the JBIG2 decoder in kpdf allow
remote attackers to cause a denial of service (crash) via a
crafted PDF file, related to (1) JBIG2SymbolDict::setBitmap and
(2) JBIG2Stream::readSymbolDictSeg.

CVE-2009-0147

Multiple integer overflows in the JBIG2 decoder in kpdf allow
remote attackers to cause a denial of service (crash) via a
crafted PDF file, related to (1) JBIG2Stream::readSymbolDictSeg,
(2) JBIG2Stream::readSymbolDictSeg, and (3)
JBIG2Stream::readGenericBitmap.

CVE-2009-0165

Integer overflow in the JBIG2 decoder in kpdf has unspecified
impact related to "g*allocn."

CVE-2009-0166

The JBIG2 decoder in kpdf allows remote attackers to cause a
denial of service (crash) via a crafted PDF file that triggers a
free of uninitialized memory.

CVE-2009-0799

The JBIG2 decoder in kpdf allows remote attackers to cause a
denial o...

Read the Full Advisory

Severity
critical
Lowest
Low
Medium
High
Critical

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here