Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

Fedora: 2009-2651 Moderate: Pdfjam Script Path Modification Fix

fedora
Calendar Grey March 13, 2009
Dist Fedora Esm H88
A security patch enhances script integrity and safeguards against name redundancy and directory alterations in pdfjam for Fedora 10 installations.
PDFjam scripts previously create temporary files with predictable names, and are also susceptible to the search path being modified

Summary

PDFjam is a small collection of shell scripts which provide a simple

interface to some of the functionality of the excellent pdfpages

package (by Andreas Matthias) for pdfLaTeX. At present the utilities

available are:

* pdfnup, which allows PDF files to be "n-upped" in roughly the way

that psnup does for PostScript files;

* pdfjoin, which concatenates the pages of multiple PDF files

together into a single file;

* pdf90, which rotates the pages of one or more PDF files through 90

degrees (anti-clockwise).

In every case, source files are left unchanged.

A potential drawback of these utilities is that any hyperlinks in the

source PDF are lost. On the positive side, there is no appreciable

degradation of image quality in processing PDF files with these

programs, unlike some other indirect methods such as "pdf2ps | psnup |

ps2pdf" (in the author's experience).

PDFjam scripts previously create temporary files with predictable names, and are

also susceptible to the search path being modified. This update fixes the two

issues.

* Thu Mar 12 2009 Michel Salim - 1.21-1

- Update to 1.21, fixing security issues CVE-2008-5743, CVE-2008-5843

(bz #480174)

[ 1 ] Bug #480174 - pdfjam: multiple security issues (CVE-2008-5743, CVE-2008-5843)

https://bugzilla.redhat.com/show_bug.cgi?id=480174

su -c 'yum update pdfjam' at the command line.

For more information, refer to "Managing Software with yum",

available at .

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

https://fedoraproject.org/security/

Fedora-package-announce mailing list

Fedora-package-announce@redhat.com

https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/

Change Log

References

Update Instructions

Severity
important
Lowest
Low
Medium
High
Critical

Product: Fedora 10
Version: 1.21
Release: 1.fc10
URL: Summary : Utilities for join, rotate and align PDFs

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here