Alerts This Week
Warning Icon 1 626
Alerts This Week
Warning Icon 1 626

Debian 5.0: DSA-2028-1 Moderate: Xpdf Remote Code Issues

debian
Calendar Grey April 5, 2010
Debian Logo
Debian DSA-2030-2 addresses vulnerabilities in Ghostscript, remedying various local and remote weaknesses to thwart exploitation via malicious PostScript files.
Several vulnerabilities have been identified in xpdf, a suite of tools for viewing and converting Portable Document Format (PDF) files

Summary

Package : xpdf
Vulnerability : multiple
Problem type : local (remote)
Debian-specific: no
Debian bug : 551287
CVE ID : CVE-2009-1188 CVE-2009-3603 CVE-2009-3604 CVE-2009-3606
CVE-2009-3608 CVE-2009-3609

Several vulnerabilities have been identified in xpdf, a suite of tools for
viewing and converting Portable Document Format (PDF) files.

The Common Vulnerabilities and Exposures project identifies the following
problems:

CVE-2009-1188 and CVE-2009-3603

Integer overflow in SplashBitmap::SplashBitmap which might allow remote
attackers to execute arbitrary code or an application crash via a crafted
PDF document.

CVE-2009-3604

NULL pointer dereference or heap-based buffer overflow in
Splash::drawImage which might allow remote attackers to cause a denial
of service (application crash) or possibly execute arbitrary code via
a crafted PDF document.

CVE-2009-3606

Integer overflow in the PSOutputDev::doImageL1Sep which might allow
remote att...

Read the Full Advisory

Package: xpdf
CVE ID: CVE-2009-1188 CVE-2009-3603 CVE-2009-3604 CVE-2009-3606

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here