Important: xpdf security update
Date: Wed, 7 Nov 2007 17:08:55 -0600
Reply-To: Connie Sieh
Sender: Security Errata for Scientific Linux
From: Connie Sieh
Subject: Security ERRATA for xpdf on SL4.x i386/x86_64
Comments: To: scientific
Synopsis: Important: xpdf security update
CVE Names: CVE-2007-4352
CVE-2007-5392
CVE-2007-5393
Problem description:
Alin Rad Pop discovered several flaws in the handling of PDF files. An
attacker could create a malicious PDF file that would cause Xpdf to crash,
or potentially execute arbitrary code when opened.
(CVE-2007-4352, CVE-2007-5392, CVE-2007-5393)
SL4.x
SRPMS:
xpdf-3.00-14.el4.src.rpm
i386:
xpdf-3.00-14.el4.i386.rpm
x86_64:
xpdf-3.00-14.el4.x86_64.rpm
-Connie Sieh