Alerts This Week
Warning Icon 1 1,149
Alerts This Week
Warning Icon 1 1,149

Fedora Core 3: FEDORA-2005-730 Critical: xpdf Disk Space Issue

fedora
Calendar Grey August 15, 2005
Dist Fedora Esm H88
Ubuntu Alert Bulletin UBUNTU-2023-2456 resolves a vulnerability in evince related to file permissions, by integrating an updated fix for enhanced data protection.
A flaw was discovered in Xpdf in that an attacker could construct a carefully crafted PDF file that would cause Xpdf to consume all available disk space in /tmp when opened.

Summary

Xpdf is an X Window System based viewer for Portable Document Format

(PDF) files. Xpdf is a small and efficient program which uses

standard X fonts.

A flaw was discovered in Xpdf in that an attacker could

construct a carefully crafted PDF file that would cause Xpdf

to consume all available disk space in /tmp when opened. The

Common Vulnerabilities and Exposures project assigned the name

CAN-2005-2097 to this issue.

Users of xpdf should upgrade to this updated package, which

contains a backported patch to resolve this issue.

- better patch to fix CAN-2005-2097, #163918

* Tue Jul 26 2005 Than Ngo 1:3.00-10.5.FC3

- backport patch to fix xpdf DoS, CAN-2005-2097, #163918

- fix xpdf crash #163807

f0fa9a37ace898d04be68f16b5a7bb14 SRPMS/xpdf-3.00-10.6.FC3.src.rpm

405fdeddfd2ca96646fcb2ae605f1c59 x86_64/xpdf-3.00-10.6.FC3.x86_64.rpm

f577bca35f06c9c74460ffad33665614

x86_64/debug/xpdf-debuginfo-3.00-10.6.FC3.x86_64.rpm

80095ec93707eb9b74872f9b49d1a99a i386/xpdf-3.00-10.6.FC3.i386.rpm

14798c621432d77e3a41ec594a47f545 i386/debug/xpdf-debuginfo-3.00-10.6.FC3.i386.rpm

This update can also be installed with the Update Agent; you can

launch the Update Agent with the 'up2date' command.

fedora-announce-list@redhat.com

Change Log

References

Update Instructions

Severity
critical
Lowest
Low
Medium
High
Critical

Name: xpdf
Version: 3.00
Release: 10.6.FC3
Summary: A PDF file viewer for the X Window System.

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here