Alerts This Week
Warning Icon 1 727
Alerts This Week
Warning Icon 1 727

Fedora: 2004-348 Critical Advisory For xpdf Integer Overflow Attack

fedora
Calendar Grey October 21, 2004
Dist Fedora Esm H88
Important patch released for Fedora tackling xpdf integer overflow vulnerabilities that may permit unauthorized code execution via specially crafted PDF files.
Chris Evans and others discovered a number of integer overflow bugs that affected all versions of xpdf

Summary

Xpdf is an X Window System based viewer for Portable Document Format

(PDF) files. Xpdf is a small and efficient program which uses

standard X fonts.

Update Information:

Xpdf is an X Window System based viewer for Portable Document Format (PDF) files.

During a source code audit, Chris Evans and others discovered a number of integer overflow bugs that affected all versions of xpdf. An attacker could construct a carefully crafted PDF file that could cause xpdf to crash or possibly execute arbitrary code when opened. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CAN-2004-0888 to this issue.

Users of xpdf are advised to upgrade to this errata package, which contains a backported patch correcting these issues. * Thu Oct 21 2004 Than Ngo <than@redhat.com> 1:3.00-3.4

- Apply patch to fix can-2004-0888, can-2004-0889

* Thu Oct 21 2004 Than Ngo <than@redhat.com> 1:3.00-3.3

- Fix xpdf crash #136633

* Tue Oct 12 2004 Than Ngo <than@redhat.com> 1:3.00-3.2

- Apply patch to fix can-2004-0888, can-2004-0889 - Fix xpdf crash when selecting outline without page reference #134993 - Fix locale issue #133911 - ...

Read the Full Advisory

Change Log

References

Fedora Update Notification FEDORA-2004-348 2004-10-21
Product : Fedora Core 2 Name : xpdf Version : 3.00 Release : 3.4 Summary : A PDF file viewer for the X Window System. Description : Xpdf is an X Window System based viewer for Portable Document Format (PDF) files. Xpdf is a small and efficient program which uses standard X fonts.

Update Instructions

Severity
critical
Lowest
Low
Medium
High
Critical

Product: Fedora Core 2
Name: xpdf
Version: 3.00
Release: 3.4
Summary: A PDF file viewer for the X Window System.

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here