CVE-2007-4352
Array index error in the DCTStream::readProgressiveDataUnit method in
xpdf/Stream.cc in Xpdf 3.02pl1, as used in poppler, teTeX, KDE, KOffice,
CUPS, and other products, allows remote attackers to trigger memory
corruption and execute arbitrary code via a crafted PDF file.
CVE-2007-5392
Integer overflow in the DCTStream::reset method in xpdf/Stream.cc in
Xpdf 3.02p11 allows remote attackers to execute arbitrary code via a
crafted PDF file, resulting in a heap-based buffer overflow.
CVE-2007-5393
Heap-based buffer overflow in the CCITTFaxStream::lookChar method in
xpdf/Stream.cc in Xpdf 3.02p11 allows remote attackers to execute
arbitrary code via a PDF file that contains a crafted CCITTFaxDecode
filter.
For the stable distribution (etch), these problems have been fixed in version
1:1.6.1-2etch2.
Updates for the old stable distribution (sarge), will be made available
as soon as possible.
We recommend that you upgrade your koffice package.
Upgrade instructions
-...
Get the latest Linux and open source security news straight to your inbox.