Alerts This Week
Warning Icon 1 535
Alerts This Week
Warning Icon 1 535

Debian DSA-2135-1 Critical: xpdf Arbitrary Code Execution

debian
Calendar Grey December 21, 2010
Debian Logo
Enhance xpdf to address threats posed by recently identified flaws that could cause arbitrary code execution.
Joel Voss of Leviathan Security Group discovered two vulnerabilities in xpdf rendering engine, which may lead to the execution of arbitrary code if a malformed PDF file is opened

Summary

Joel Voss of Leviathan Security Group discovered two vulnerabilities
in xpdf rendering engine, which may lead to the execution of arbitrary
code if a malformed PDF file is opened.

For the stable distribution (lenny), these problems have been fixed in
version 3.02-1.4+lenny3.

For the upcoming stable distribution (squeeze) and the unstable
distribution (sid), these problems don't apply, since xpdf has been
patched to use the Poppler PDF library.

We recommend that you upgrade your poppler packages.

Upgrade instructions
- --------------------

If you are using the apt-get package manager, use the line for
sources.list as given below:

apt-get update
will update the internal database
apt-get upgrade
will install corrected packages

You may use an automated update by adding the resources from the
footer to the proper configuration.

For apt-get: deb https://www.debian.org/security/ stable/updates main
For dpkg-ftp: dists/stable/updates/main

Package i...

Read the Full Advisory

Severity
critical
Lowest
Low
Medium
High
Critical

Package: xpdf

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here