Important: poppler security update
Date: Tue, 31 Jul 2007 14:13:20 -0500
Reply-To: Troy Dawson
Sender: Security Errata for Scientific Linux
From: Troy Dawson
Subject: Security ERRATA for poppler on SL5.x i386/x86_64
Comments: To: This email address is being protected from spambots. You need JavaScript enabled to view it.
Synopsis: Important: poppler security update
Issue date: 2007-07-30
CVE Names: CVE-2007-3387
Maurycy Prodeus discovered an integer overflow flaw in the processing
of PDF files. An attacker could create a malicious PDF file that would
cause an application linked with poppler to crash or potentially execute
arbitrary code when opened. (CVE-2007-3387)
SL 5.x
SRPMS:
poppler-0.5.4-4.1.el5.src.rpm
i386:
poppler-0.5.4-4.1.el5.i386.rpm
poppler-devel-0.5.4-4.1.el5.i386.rpm
poppler-utils-0.5.4-4.1.el5.i386.rpm
x86_64:
poppler-0.5.4-4.1.el5.i386.rpm
poppler-0.5.4-4.1.el5.x86_64.rpm
poppler-devel-0.5.4-4.1.el5.i386.rpm
poppler-devel-0.5.4-4.1.el5.x86_64.rpm
poppler-utils-0.5.4-4.1.el5.x86_64.rpm
-Connie Sieh
-Troy Dawson
lastline