Alerts This Week
Warning Icon 1 637
Alerts This Week
Warning Icon 1 637

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 0 articles for you...
87

Debian: DSA 1019-1 Important: Kpdf Local Security Risks and Fixes

Derek Noonburg has fixed several potential vulnerabilities in xpdf, the Portable Document Format (PDF) suite, which is also present in koffice, the KDE Office Suite.. - --------------------------------------------------------------------------Debian Security Advisory DSA 1019-1 This email address is being protected from spambots. You need JavaScript enabled to view it. http://www.debian.org/security/ Martin Schulze March 24th, 2006 http://www.debian.org/security/faq - --------------------------------------------------------------------------Package : koffice Vulnerability : several Problem type : local (remote) Debian-specific: no CVE ID : CVE-2006-1244 Bugtraq ID : 16748 Derek Noonburg has fixed several potential vulnerabilities in xpdf, the Portable Document Format (PDF) suite, which is also present in koffice, the KDE Office Suite. The old stable distribution (woody) does not contain kpdf packages. For the stable distribution (sarge) these problems have been fixed in version 1.3.5-4.sarge.3. For the unstable distribution (sid) these problems will be fixed soon. We recommend that you upgrade your kpdf package. Upgrade Instructions - --------------------wget url will fetch the file for you dpkg -i file.deb will install the referenced file. If you are using the apt-get package manager, use the line for sources.list as given below: apt-get update will update the internal database apt-get upgrade will install corrected packages You may use an automated update by adding the resources from the footer to the proper configuration. Debian GNU/Linux 3.1 alias sarge - -------------------------------- Source archives: Size/MD5 checksum: 975 5968b7cf5d069e98ba8fe6512b6f656c Size/MD5 checksum: 21789 52604c90cca5685c2cecba3e418066d1 Size/MD5 checksum: 13154501 2c9b45ecbf16a8c5d16ce9d2f51c2571 Architecture independent components: Size/MD5 checksum: 623568c53b00698e81328e5526fe40cbd4522e Size/MD5 checksum: 692792 a8e0f9cbb192c88a23f42bd3e62836d4 Size/MD5 checksum: 295700 5cb99cee3874acbd20344315c2fc8dc7 Size/MD5 checksum: 21672 b27effec8464b005b354072a612365a9 Alpha architecture: Size/MD5 checksum: 923332 f45bb0425f6f39ecc521f6bf10484374 Size/MD5 checksum: 715538 e6bcecf6bea0bcda1c2728e1b2a7495d Size/MD5 checksum: 703440 346bf50fda8dfaec02a90a8e0d0e54c3 Size/MD5 checksum: 633042 7a824bf8ff0108fcadc4b249e2c3eea3 Size/MD5 checksum: 154722 ef84303285cfe0e1f529bbf8d19178d2 Size/MD5 checksum: 2307112 be91472dd188946a10b8893794825aa5 Size/MD5 checksum: 59784 2ac5aa0b6ee6103347717c7e0bf1bced Size/MD5 checksum: 2603222 3cf494f98a30f24ad5bad6c64cc8d730 Size/MD5 checksum: 1851030 1603d191a1c8d7f35909830c4c7cd78e Size/MD5 checksum: 566634 b739c228f6ae2e03b5c205858425b3d2 Size/MD5 checksum: 3768746 ce22e335fb911f30c4175c4fcd43095a AMD64 architecture: Size/MD5 checksum: 860396 a2a44915558aaa5a69548d6b6cffea73 Size/MD5 checksum: 681242 a789c3a842ae8e777dacac43eba7284e Size/MD5 checksum: 700730 2829e4b27e14457e713435319268f97b Size/MD5 checksum: 588172 5528f55d628ed08f09993ca03f314981 Size/MD5 checksum: 154722 061504d68d3e413556d444a8f4218290 Size/MD5 checksum: 2137612 77cd21a733ec8168ac89f7980ba25b51 Size/MD5 checksum: 58316 9ff472c5d249638f72dc4b4b97babdbf Size/MD5 checksum: 2540042 14ebc25e1571e787b20db77f29c06c81 Size/MD5 checksum: 1759030 4c50c15b119a976f1de27951d5911713 Size/MD5 checksum: 558026 b15d1bd5a09b8383d3b0e057a60a4cc9 Size/MD5 checksum: 3588538 528c12df665b8cb8e1112d2eb25b52c5 ARM architecture: Size/MD5 checksum: 763510 166a047fb9b7ce9a0c9b5bba75d4ed81 Size/MD5 checksum: 6413745d93cdf80b4f229e1e3cb482fe9cea41 Size/MD5 checksum: 694452 5353a078cfec5f1014bd22ffb1c4bda9 Size/MD5 checksum: 514320 74078f115cfb0920328eaffd3c5390fb Size/MD5 checksum: 154752 8b69648ba4d60b69d5c18d02cf840674 Size/MD5 checksum: 2022882 e2528be72f5ef4aa2ef283bd29c76781 Size/MD5 checksum: 56290 8fa5cc227d8d80473728ee6a8db47c6e Size/MD5 checksum: 2431144 a18e53aa05816e5b6a057d9bdcb3ce2b Size/MD5 checksum: 1598452 753b634da920411f464c2937bf38b9e3 Size/MD5 checksum: 521050 2ed9bb3a7a44e361349de7bd9876d688 Size/MD5 checksum: 3354918 5170f56249017150a25c90fce503d4b2 Intel IA-32 architecture: Size/MD5 checksum: 804952 8e13a2675ce9286fef6372658f4cf3ff Size/MD5 checksum: 680582 a7f89f83f4d19cc011f91715ddfa92b4 Size/MD5 checksum: 698060 5270568afc2a1acc058215cb164fc16b Size/MD5 checksum: 561414 2f8eeaf6ee707dd90d9fa88346758bd6 Size/MD5 checksum: 154718 a5911dad6af6c80632bb7c40e185f7f7 Size/MD5 checksum: 2058312 05e1426860580a88d0c630a5d28ae720 Size/MD5 checksum: 56610 377f3f62cd2fcf1c9d30e31f87f7b389 Size/MD5 checksum: 2534878 fdea86449af2a011b69537ff978a3379 Size/MD5 checksum: 1727124 e79c7c97c2a38bccb27c6c5421d2a48f Size/MD5 checksum: 548106 7d48803ff8c5f59c1cf544ccd2b7e08f Size/MD5 checksum: 3508212 355d85842f3bd7f5a6509f45a6dbf1db Intel IA-64 architecture: Size/MD5 checksum: 1050380 3042e7da052f77890d50d82de745293c Size/MD5 checksum: 800764 515b76aea5ae91214dc15a332381d948 Size/MD5 checksum: 713452 250240ace7692094fa444e2a9ccea3b3 Size/MD5 checksum: 720688 59f9b28e32d026da8ce4d899b5ce7e89 Size/MD5 checksum: 154734 d60f33c56bf8ec1485d3995493c84834 Size/MD5 checksum: 2671254 0fc0b5c4f37f3f3359d59148d7e6bed5 Size/MD5 checksum: 65186 20cc5bb118751234dcd42627b481897f Size/MD5 checksum: 2803326 84bbd392b82a0cd69bda36c5a01bdcd7 Size/MD5 checksum: 2153590 d92defdef242687c8e8e2c8281a2e4b3 Size/MD5 checksum: 616300 fa376d046a57fe17eb76fb14b20a9331 Size/MD5 checksum: 4183212 9e19eec25bfe7c077fe0540590785b10 HP Precision architecture: Size/MD5 checksum: 942554 7efd73ef745ee08e2b2bb025112a5e9c Size/MD5 checksum: 716310 1952b962280a889b5f4432fdd0d5c369 Size/MD5 checksum: 706996 ebb919db9520b41b86d8095fc010af0f Size/MD5 checksum: 645244 0791e7f5b5bf24c01e177ad0b9c623ed Size/MD5 checksum: 154742 e8652ec791eb215684150e714211550f Size/MD5 checksum: 2444088 024b796dcbef31c3b3c0329c23718ec7 Size/MD5 checksum: 62128 3eee3a3209f8eee701e596f72dc2fcbb Size/MD5 checksum: 2637796 3d10d7b95797aad299ce43a01f49ab77 Size/MD5 checksum: 1890288 e86b1c523fda48b27c2950e7eab5a29a Size/MD5 checksum: 580852 70fb5040226735cdcd0eb991f54e1c09 Size/MD5 checksum: 3799176 3283552db3f78ca8a0178130379edfc1 Motorola 680x0 architecture: Size/MD5 checksum: 819530 72f2b666f83edd4679b0f0efd0361188 Size/MD5 checksum: 644278 a627c249771a4b1196f57935e675c7a9 Size/MD5 checksum: 700476 f558aa71e30c175c6680e49e112fe18e Size/MD5 checksum: 548680 aa3a24851768e1ecaf947253ae8af8f1 Size/MD5 checksum: 154768 5410d85b1ce2f6aaf557125e90792025 Size/MD5 checksum: 2077696 bd69ed0b94580350162d1e119de8013c Size/MD5 checksum: 59870 e74bc84d33859f6c22c0f1341b97bf20 Size/MD5 checksum: 2470076 01ea87f755a215795703e102e6ee9529 Size/MD5 checksum: 1631250 13d1b87fb743fd55bb44623a81aea0d9 Size/MD5 checksum: 539766 c472ba091388145bdb7be77df8f8cf27 Size/MD5 checksum: 3451048 8ab6bb53374f289f65dbc3c9bf090c9e Big endian MIPS architecture: Size/MD5 checksum: 780422 852916eb9f1c8e415613d0c87ff2a2ef Size/MD5 checksum: 629844 9d0722e5c91d95be87c0cb4b1e5dce1d Size/MD5 checksum: 693670 022cfe4c9344e78fec91a46b47d75f37 Size/MD5 checksum: 529776 a5aab94d246a3ec4cbf9ca1d0911e6f9 Size/MD5 checksum: 154730 b275c42cdd121afa8922a30d47b17b14 Size/MD5 checksum: 1870358 0dcbc0b8a1b7452c9ab4172f1c79a716 Size/MD5 checksum: 56130 cb8fbd4e8d1ae9de28b74246af63cb2d Size/MD5 checksum: 2392040 6bfd97473a54451ea0909fede944da99 Size/MD5 checksum: 1489490 302e62a6a31ce29153e3f59f66618b00 Size/MD5 checksum: 499626 70d178e9c516ef505e0bd2d30e2b3d88 Size/MD5 checksum: 3320902 07a166576b5a21e8d236809e35438269 Little endian MIPS architecture: Size/MD5 checksum: 772822 60f1bde9c225e029243f7fc94c09ffef Size/MD5 checksum: 626454 deaa8450f32ec7a7e6b1a20864dd02df Size/MD5 checksum: 693436 ceb74e20460c778e335b044f2f92ed41 Size/MD5 checksum: 521158 be01403f734be4ea63ae9b724124a308 Size/MD5 checksum: 154766 0c1e6ffaecafd20203ae93a5cb1fca73 Size/MD5 checksum: 1839052 a71f620b20b83e771a27b3b762abeaaf Size/MD5 checksum: 56292 62add2393215a16c93b5dc00b6bc6fc2 Size/MD5 checksum: 2378062 1ae60d2ad1b81912936d84d15ff93c85 Size/MD5 checksum: 1478568 fcdc50004e00febaaa1089061d2bc238 Size/MD5 checksum: 497740 b2eb83f8d8c282b2b2b74bac9ec5c824 Size/MD5 checksum: 3299058 b1d445de632afac1c9167cd7e3ace0c1 PowerPC architecture: Size/MD5 checksum: 832506 bdf109d934d3b85fb2c31b3dc1b74f9c Size/MD5 checksum: 658868 ba7d4a824f541da2709902d36964f3c4 Size/MD5 checksum: 698530 27492a8ed9c10569538f2661dca9b174 Size/MD5 checksum: 561106 2686f4ecd5fe0c80e49a0669a8f69b7e Size/MD5 checksum: 154756 3ee7545260b85f2bafe329243329819d Size/MD5 checksum: 2024150 ca8db5fbeedd573585cecea59c19d11d Size/MD5 checksum: 58916 7c0cd98f224e71aa282e6fd01b8aa85b Size/MD5 checksum: 2480464 0d0a536191e38cb9980f6e0a6e770965 Size/MD5 checksum: 1667348 971051b62c1d18174edc53f2b0baee4a Size/MD5 checksum: 541464 f1c0f77fadfc909b53c0613924c76b19 Size/MD5 checksum: 3495820 87701dbe9394b176158202c164485513 IBM S/390 architecture: Size/MD5 checksum: 856762 10de3110045b825cb2e009137bc08aa8 Size/MD5 checksum: 663776 3a6cb0c54b0c651bdf16ebc1e5ce9cda Size/MD5 checksum: 701596 6b46f93d91c9ee2de35f186cc86390b8 Size/MD5 checksum: 595358 1537238ff38cb89f26dad6cf9901b369 Size/MD5 checksum: 154730 abff9e88df63342310828a2f09c6c0bc Size/MD5 checksum: 2079748 88b17d408419aafe7ba2598b5e279530 Size/MD5 checksum: 58878 b68898324b97aac85011f436355cc7ad Size/MD5 checksum: 2496824 199dcf90afe29acbeb1ffc0c92f6ee02 Size/MD5 checksum: 1667266 4a3fb4318b080a989799906a2e7b2145 Size/MD5 checksum: 528326 985f401384ed4d233691de42acb1ad74 Size/MD5 checksum: 3564230 786e2b40840b6106382688859da19986 Sun Sparc architecture: Size/MD5 checksum: 781884 e439fb224dcec5f9277537dc5e84d0e3 Size/MD5 checksum: 654574 1063ffb2fab6efad0540fb0a2936e073 Size/MD5 checksum: 694654 bc677f7c221f204322066bb91e8922b9 Size/MD5 checksum: 540890 b67030c6ba668a4787f7e03b8b2f8568 Size/MD5 checksum: 154730 cf78f5b49885bf83ea4be8810a09cd19 Size/MD5 checksum: 1956214 fc3c70041fbaee003178a2aac354ef6d Size/MD5 checksum: 55450 613db28a6ac14303e87edf89c82dcc2b Size/MD5 checksum: 2471268 d0cbcf36607e6c6822e7e0c331507ba2 Size/MD5 checksum: 1649084 54a5dbab59278bedf15c7d61581c0ad3 Size/MD5 checksum: 523670 9ee93556989a0b6f88b7c15638a0f4f3 Size/MD5 checksum: 3425960 9bd6d818dc741f5782329fa4f1358797 These files will probably be moved into the stable distributionon its next update. - ---------------------------------------------------------------------------------For apt-get: deb https://www.debian.org/security/ stable/updates main For dpkg-ftp: dists/stable/updates/main Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Ubuntu Security Notice USN 1234-5 highlights vulnerabilities in evince. Users are urged to update for improved document protection and integrity.. debian Security Advisory,kpdf Issues,xpdf Patch,Document Protection,Software Upgrade. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Mar 24, 2006 Important Debian
99

Slackware: 2006-045-04 Critical: KPDF Buffer Overflow Security Fix

New kdegraphics packages are available for Slackware 10.0, 10.1, 10.2, and -current to fix security issues with kpdf. More details about these issues may be found in the Common Vulnerabilities and Exposures (CVE) database: . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 [slackware-security] kdegraphics (SSA:2006-045-04) New kdegraphics packages are available for Slackware 10.0, 10.1, 10.2, and -current to fix security issues with kpdf. More details about these issues may be found in the Common Vulnerabilities and Exposures (CVE) database: https://www.cve.org/CVERecord?id=CVE-2005-3191 https://www.cve.org/CVERecord?id=CVE-2005-3192 https://www.cve.org/CVERecord?id=CVE-2005-3193 https://www.cve.org/CVERecord?id=CVE-2005-3624 https://www.cve.org/CVERecord?id=CVE-2005-3625 https://www.cve.org/CVERecord?id=CVE-2005-3626 https://www.cve.org/CVERecord?id=CVE-2005-3627 https://www.cve.org/CVERecord?id=CVE-2005-3628 https://www.cve.org/CVERecord?id=CVE-2006-0301 Additional information is also available from the KDE website: https://kde.org/info/security/advisory-20051207-2.txt https://kde.org/info/security/advisory-20060202-1.txt Here are the details from the Slackware 10.2 ChangeLog: +--------------------------+ patches/packages/kdegraphics-3.4.2-i486-2.tgz: Patched integer and heap overflows in kpdf to fix possible security bugs with malformed PDF files. For more information, see: https://kde.org/info/security/advisory-20051207-2.txt https://kde.org/info/security/advisory-20060202-1.txt https://www.cve.org/CVERecord?id=CVE-2005-3191 https://www.cve.org/CVERecord?id=CVE-2005-3192 https://www.cve.org/CVERecord?id=CVE-2005-3193 https://www.cve.org/CVERecord?id=CVE-2005-3624 https://www.cve.org/CVERecord?id=CVE-2005-3625 https://www.cve.org/CVERecord?id=CVE-2005-3626 https://www.cve.org/CVERecord?id=CVE-2005-3627 https://www.cve.org/CVERecord?id=CVE-2005-3628 https://www.cve.org/CVERecord?id=CVE-2006-0301 (* Security fix*) +--------------------------+ Where to find the new packages: +-----------------------------+ Updated package for Slackware 10.0: ftp://ftp.slackware.com/pub/slackware/slackware-10.0/patches/packages/kdegraphics-3.2.3-i486-2.tgz Updated package for Slackware 10.1: Updated package for Slackware 10.2: Updated package for Slackware -current: MD5 signatures: +-------------+ Slackware 10.0 package: da13535a269210c3e8aff65ef17e2442 kdegraphics-3.2.3-i486-2.tgz Slackware 10.1 package: 1499ba1755da9e69a6b69031b2919eb2 kdegraphics-3.3.2-i486-4.tgz Slackware 10.2 package: 5bb6d9647f5d48d00cbd698e9aa5821e kdegraphics-3.4.2-i486-2.tgz Slackware -current package: a3dc06eee3e19500f39ee1ecbac977e1 kdegraphics-3.5.1-i486-1.tgz Installation instructions: +------------------------+ Upgrade the package as root: # upgradepkg kdegraphics-3.4.2-i486-2.tgz +-----+ . Kdegraphics security patch released for Slackware addressing severe vulnerabilities found in kpdf application.. Kdegraphics Update, Slackware Security, Package Vulnerability, KPDF Issues. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Feb 15, 2006 Critical Slackware
91

Gentoo GLSA-200602-05 Normal: KPdf Heap Overflow Risk from PDF Files

KPdf includes vulnerable Xpdf code to handle PDF files, making it vulnerable to the execution of arbitrary code.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200602-05 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: KPdf: Heap based overflow Date: February 12, 2006 Bugs: #121375 ID: 200602-05 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= KPdf includes vulnerable Xpdf code to handle PDF files, making it vulnerable to the execution of arbitrary code. Background ========= KPdf is a KDE-based PDF viewer included in the kdegraphics package. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 kde-base/kdegraphics < 3.4.3-r4 > = 3.4.3-r4 2 kde-base/kpdf < 3.4.3-r4 > = 3.4.3-r4 ------------------------------------------------------------------- 2 affected packages on all of their supported architectures. ------------------------------------------------------------------- Description ========== KPdf includes Xpdf code to handle PDF files. Dirk Mueller discovered that the Xpdf code is vulnerable a heap based overflow in the splash rasterizer engine. Impact ===== An attacker could entice a user to open a specially crafted PDF file with Kpdf, potentially resulting in the execution of arbitrary code with the rights of the user running the affected application. Workaround ========= There is no known workaround at this time. Resolution ========= All kdegraphics users should upgrade to the latestversion: # emerge --sync # emerge --ask --oneshot --verbose "> =kde-base/kdegraphics-3.4.3-r4" All Kpdf users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =kde-base/kpdf-3.4.3-r4" References ========= [ 1 ] CVE-2006-0301 https://www.cve.org/CVERecord?id=CVE-2006-0301 [ 2 ] KDE Security Advisory: kpdf/xpdf heap based buffer overflow https://kde.org/info/security/advisory-20060202-1.txt Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/200602-05 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users machines is of utmost importance to us. Any security concerns should be addressed to This email address is being protected from spambots. You need JavaScript enabled to view it. or alternatively, you may file a bug at https://bugs.gentoo.org/. License ====== Copyright 2006 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. https://creativecommons.org/licenses/by-sa/2.0/ . KPdf on Gentoo exposed to heap overflow vulnerability; update to the most recent version to prevent exploitation via specially crafted PDF documents.. KPdf Security,Gentoo Updates,Heap Overflow Risk,PDF Code Execution. . LinuxSecurity.com Team

Calendar 2 Feb 13, 2006 Gentoo
89

Fedora Core 4: 2006-105 Critical Vulnerability in kpdf Buffer Overflow

kpdf, the KDE pdf viewer, shares code with xpdf. xpdf contains a heap based buffer overflow in the splash rasterizer engine that can crash kpdf or even execute arbitrary code. Users impacted by these issues, should update to this new package release. . ---------------------------------------------------------------------Fedora Update Notification FEDORA-2006-105 2006-02-10 ---------------------------------------------------------------------Product : Fedora Core 4 Name : kdegraphics Version : 3.5.1 Release : 0.2.fc4 Summary : K Desktop Environment - Graphics Applications Description : Graphics applications for the K Desktop Environment. Includes: kdvi (displays TeX .dvi files) kfax (displays faxfiles) kghostview (displays postscript files) kcoloredit (palette editor and color chooser) kamera (digital camera support) kiconedit (icon editor) kpaint (a simple drawing program) ksnapshot (screen capture utility) kview (image viewer for GIF, JPEG, TIFF, etc.) kuickshow (quick picture viewer) kooka (scanner application) kruler (screen ruler and color measurement tool) ---------------------------------------------------------------------Update Information: kpdf, the KDE pdf viewer, shares code with xpdf. xpdf contains a heap based buffer overflow in the splash rasterizer engine that can crash kpdf or even execute arbitrary code. Users impacted by these issues, should update to this new package release. ---------------------------------------------------------------------* Tue Feb 7 2006 Than Ngo 7:3.5.1-0.2.fc4 - apply patch to fix buffer overflow in kpdf, CVE-2006-0301 (#179056) ---------------------------------------------------------------------This update can be downloaded from: 4ed4ed8ca7762a7140b4aea37862078bc3758988 SRPMS/kdegraphics-3.5.1-0.2.fc4.src.rpm 3a9a3b3777eff2ac02ff21ba78151d25c3395a9d ppc/kdegraphics-3.5.1-0.2.fc4.ppc.rpm 9c25998f60be8531e2e1a4366611501d2adee26e ppc/kdegraphics-devel-3.5.1-0.2.fc4.ppc.rpm 296f883442cba8315c5b23799d3488ffaa843c89 ppc/debug/kdegraphics-debuginfo-3.5.1-0.2.fc4.ppc.rpm 03990a0a90d0bc769494759727b2e76f20cde814 x86_64/kdegraphics-3.5.1-0.2.fc4.x86_64.rpm 2ab08e61a5137f1833f8ca815a5dc025aba38ae6 x86_64/kdegraphics-devel-3.5.1-0.2.fc4.x86_64.rpm 9c539d49ecc4be772816d8c3989951736d7454a3 x86_64/debug/kdegraphics-debuginfo-3.5.1-0.2.fc4.x86_64.rpm a99acaa35091e76a25a51acad2e7fe0a3719720d i386/kdegraphics-3.5.1-0.2.fc4.i386.rpm ce4cc146300daa51cb37089de8aefbd407a7a102 i386/kdegraphics-devel-3.5.1-0.2.fc4.i386.rpm 5b918d77c186fa41958dc5ac503e2367afe23c58 i386/debug/kdegraphics-debuginfo-3.5.1-0.2.fc4.i386.rpm This update can be installed with the 'yum' update program. Use 'yum update package-name' at the command line. For more information, refer to 'Managing Software with yum,' available at . ----------------------------------------------------------------------- fedora-announce-list mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . Patch release for Fedora Core 4 addresses a significant memory corruption issue in kpdf, enhancing both security and performance. Download immediately.. Fedora Update,kdegraphics buffer overflow,kpdf update,critical security patch,graphics applications. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Feb 10, 2006 Critical Fedora
87

Debian 3.1 DSA-932-1 Critical: KPDF Buffer Overflow Impacting Users

"infamous41md" and Chris Evans discovered several heap based buffer overflows in xpdf, the Portable Document Format (PDF) suite, that can lead to a denial of service by crashing the application or possibly to the execution of arbitrary code. The same code is present in kpdf which is part of the kdegraphics package. . - --------------------------------------------------------------------------Debian Security Advisory DSA 932-1 This email address is being protected from spambots. You need JavaScript enabled to view it. http://www.debian.org/security/ Martin Schulze January 9th, 2006 http://www.debian.org/security/faq - --------------------------------------------------------------------------Package : xpdf Vulnerability : buffer overflows Problem type : remote Debian-specific: no CVE IDs : CVE-2005-3191 CVE-2005-3192 CVE-2005-3193 CVE-2005-3624 CVE-2005-3625 CVE-2005-3626 CVE-2005-3627 CVE-2005-3628 Debian Bug : 342281 "infamous41md" and Chris Evans discovered several heap based buffer overflows in xpdf, the Portable Document Format (PDF) suite, that can lead to a denial of service by crashing the application or possibly to the execution of arbitrary code. The same code is present in kpdf which is part of the kdegraphics package. The old stable distribution (woody) does not contain kpdf packages. For the stable distribution (sarge) these problems have been fixed in version 3.3.2-2sarge3. For the unstable distribution (sid) these problems have been fixed in version 3.5.0-3. We recommend that you upgrade your kpdf package. Upgrade Instructions - --------------------wget url will fetch the file for you dpkg -i file.deb will install the referenced file. If you are using the apt-get package manager, use the line for sources.list as given below: apt-get update will update the internal database apt-get upgrade will install corrected packages You may use an automated update by adding theresources from the footer to the proper configuration. Debian GNU/Linux 3.1 alias sarge - -------------------------------- Source archives: Size/MD5 checksum: 1317 883261a391a85afb038bb7ea2150ecd7 Size/MD5 checksum: 159106 1169ddf001b77319f2859c87ce482bc4 Size/MD5 checksum: 7661488 6d0bb2c6e2e2f666d123778fbc520317 Architecture independent components: Size/MD5 checksum: 17620 9c3f491df5dcb49a81b26062df50ea98 Alpha architecture: Size/MD5 checksum: 92500 5a48e6e37e72346756b6153dea64cb03 Size/MD5 checksum: 109094 2c0eef65ec4eeb3ed658efdbfb8783e8 Size/MD5 checksum: 64974 7eb446cb432616cc6caa48b3eef3e6b1 Size/MD5 checksum: 276194 7f1b3ceabb2e6bfbd3bf6286833e69a8 Size/MD5 checksum: 497566 9a2bb4bb6e4bc14a4e37d38791d7eb21 Size/MD5 checksum: 149330 5ee25f6cbc684023ed30bf965d86ada8 Size/MD5 checksum: 92958 4170a1ba0e59a2af45780bb4f45b5763 Size/MD5 checksum: 245964 8377a72e9f7739c74cdcb22326d48e0f Size/MD5 checksum: 159532 0edc3bcc04d6f54be88002bbb713931a Size/MD5 checksum: 244546 c2095b637627385e2630892c60b0fbb9 Size/MD5 checksum: 831188 c9c211bd627e7466a9ac9601b3adbfa6 Size/MD5 checksum: 774074 77de1419dadbe632654580ba685bf0f8 Size/MD5 checksum: 534432 f5986e5949252346fcc57e5f0732b3c5 Size/MD5 checksum: 2317542 fb2095e8e363d4d79953a899fafa6296 Size/MD5 checksum: 63414 0a3e195e572178fc40f0d1fd0e54077d Size/MD5 checksum: 103090 acfc3b3d030f748a5b7e1e8247d90938 Size/MD5 checksum: 1357640 bba569d594464e09d8389f53580a562c Size/MD5 checksum: 483788 bf0e57bf80bafa78ece4734d16e5c720 Size/MD5 checksum: 695424 47141779a11b3ed4d52373d21f3d0199 Size/MD5 checksum: 183880 85eaebeedbb011b5ba8d237c9a773363 Size/MD5 checksum: 33092 294ab0b1581c856d3a05dfb4d771772d Size/MD5checksum: 148226 51ca1b3297696bbe103b34c1e692f10e AMD64 architecture: Size/MD5 checksum: 87972 60ca2731887c79514aad0535af7ce5a6 Size/MD5 checksum: 100302 afa754568e0f5e3b1b08208c070ea80b Size/MD5 checksum: 64970 13ead70c497d1abe4d8e0b64054673e0 Size/MD5 checksum: 252140 4d3a0b70d7a21e29b598a8fdfa078e1f Size/MD5 checksum: 485710 ec9300643ce00f9c6194f35d5935b7d0 Size/MD5 checksum: 144900 a98182043ec1e0ddf008a94f8e9f6b39 Size/MD5 checksum: 87874 459b38e1e638dcd1a402f677b0d72ddb Size/MD5 checksum: 234010 d591becbe09936e1d6ca04c2afc91fce Size/MD5 checksum: 143496 ffd0abcf446a1a5df52ff1d3034525a0 Size/MD5 checksum: 233908 374d3456398f6c282c2e1f038d180872 Size/MD5 checksum: 767986 448ef8aa521118792792f0f7c9743497 Size/MD5 checksum: 759638 ba8104609502f55782e5b1e88a177c93 Size/MD5 checksum: 485858 7cebf4d6a0c863aee628c0a13ca57435 Size/MD5 checksum: 2233414 a4d0efeb95af95c396eecf9d34645c42 Size/MD5 checksum: 63094 c14bc4abc51418dd6a43c4925b7ab8ff Size/MD5 checksum: 99826 e6b6c796dc699297438449788f1385bd Size/MD5 checksum: 1223444 7b995aadba63947f3c16c26d60af7c04 Size/MD5 checksum: 477640 99e831229b3434c714bfbfe3b06d67c6 Size/MD5 checksum: 678640 ed56083f0c5d480e6b030bbe46cf39c5 Size/MD5 checksum: 173234 ea854daab244c805f22fab1ef00c4501 Size/MD5 checksum: 33092 8a0f5e5ccdec0da1715a228d6e918be7 Size/MD5 checksum: 140160 943f60daa34a3022cdf1e61a74be6727 ARM architecture: Size/MD5 checksum: 82404 7cde7db938cb953a501d3042a1533859 Size/MD5 checksum: 88398 02d60aceb08f53faf77f10ae59aa170f Size/MD5 checksum: 64994 8039a436f88742aaef37358b86a2522b Size/MD5 checksum: 222994 b8e5d381f364876dd65d7f90eeb432f6 Size/MD5 checksum: 471280676d721e8731aa075dcb33411fe39e15 Size/MD5 checksum: 137266 c27349004cbc42a68a0e62f622ee6f75 Size/MD5 checksum: 84972 260016c06dde14b7e4e6c4dc9da6b1c7 Size/MD5 checksum: 217514 91a5acde5bb21adc9e197f78f30c1bbd Size/MD5 checksum: 127548 ee8f84522aa0ea8fe92653901d40f3ab Size/MD5 checksum: 210264 4f63ea87da3f3a63d6fed1935593348f Size/MD5 checksum: 712230 d58a0fcd3ea98346d14bc9845f3ad9bd Size/MD5 checksum: 739682 97d75f7b75ff91a8332d59045de83dc1 Size/MD5 checksum: 424114 1152a75238667a9593905bbd40038be1 Size/MD5 checksum: 2095184 7ac33f99bea7667b03ab3c1c86870c67 Size/MD5 checksum: 59256 deed7c4085f53831f63191526d5390e6 Size/MD5 checksum: 93348 40f906de514a2593d7dad7ba7f13210a Size/MD5 checksum: 1310486 d97b0bb5e736350a506f0a64dd57e75d Size/MD5 checksum: 465466 3f9d7de13c7aeeb827aef0c7bfb994cc Size/MD5 checksum: 641312 480c12a4a3d0ca2195bb9ae374d3e582 Size/MD5 checksum: 155152 8798f061114f9a6fb019d20fcdcae533 Size/MD5 checksum: 33094 b2469fd24237631256b1d5e5efe8f733 Size/MD5 checksum: 124204 0073a82d7a0ada3716163d082a99a18a Intel IA-32 architecture: Size/MD5 checksum: 85920 1f8dccfa7b64c34f08cfab3d6c88a2d5 Size/MD5 checksum: 95446 fc147588e733eb66d6a2614b3da77560 Size/MD5 checksum: 64968 95f5c54d6b0d7205ee7580abd066f37d Size/MD5 checksum: 222032 d91de9dd780ff410d01627b8062fd23f Size/MD5 checksum: 483864 df6ef6393a0aa1694e0767a425da1c57 Size/MD5 checksum: 140482 0ee2d3187a06af8e7e1f43ea90886c01 Size/MD5 checksum: 85876 6deee36ae927df2b9c43075946d0c363 Size/MD5 checksum: 227452 7a03c8c5ae46d8776538555b67ebddd8 Size/MD5 checksum: 135884 52eb8e5cbccf5952cacffab1ab8bb6ee Size/MD5 checksum: 221742 f994714fee52570758cca71a04099870 Size/MD5 checksum: 748352 aff6500c8e7b6347cb2cfce12e761318 Size/MD5 checksum: 750644 8c662c18ac1d5234e99b7ac304570fa6 Size/MD5 checksum: 452124 ea5f910e36dd17810d01e0ede44187f1 Size/MD5 checksum: 2205646 62e1fd98168e576ae78986e7cf88fadf Size/MD5 checksum: 62548 0866b72eb70749a328304996b5da6245 Size/MD5 checksum: 97222 f4e1290335928e9b76b2715135a23516 Size/MD5 checksum: 1220820 c86f6657d183e99e8a69a11c741543c7 Size/MD5 checksum: 472032 7558051b7f3432ae2b5088c79afbc906 Size/MD5 checksum: 643484 3d7111575de51a703afefc6de1b64d59 Size/MD5 checksum: 166918 bf6a7f7b5018c5e9d3fbf8c0804bc4a0 Size/MD5 checksum: 33098 693fd2750e0678a95ab13df3d443c320 Size/MD5 checksum: 134532 09327e3fa166ffd9e4606338b936ee86 Intel IA-64 architecture: Size/MD5 checksum: 102406 51fdcb159c85449f909f7d74c20f0aa1 Size/MD5 checksum: 117808 017a9c64eaff071bbe3e91d0c8bdc91f Size/MD5 checksum: 64968 2bfd3bf06bf9a4ef822a7289fbd7cc43 Size/MD5 checksum: 322930 3997e095f2530c1bbcd229ecb9836f24 Size/MD5 checksum: 540612 5258387412c170df5f9fa19fcd8dfaaf Size/MD5 checksum: 160086 d15976032f48a9e120c6b56776f8342f Size/MD5 checksum: 103936 21d42fecd9a1fceac1cbef91cbb68c96 Size/MD5 checksum: 280826 d8242161f03e63ba52162775e62ad101 Size/MD5 checksum: 176204 21237877e70bc93a8371ab0aa5faf220 Size/MD5 checksum: 277288 8ca48ad52ffae22c953b88d44abfdd1f Size/MD5 checksum: 888426 edce61c7a9a65ef65c9dd08d2ea83fd7 Size/MD5 checksum: 799002 9abe5f38e0781adbf404ec1105c0e9df Size/MD5 checksum: 629398 801d1509b6dccd250d5dc3757ecadee8 Size/MD5 checksum: 2537880 4e7c3dba6e19729547b22a8c7dcfa0b7 Size/MD5 checksum: 67780 686786077def8ae34c3132188521993e Size/MD5 checksum: 108160 2a09dbbe80ea1624d9a1a2b1b261ab7a Size/MD5 checksum: 1417144 cc3cfe3e709d5862283e580a0820f283 Size/MD5 checksum: 501596 2a80a9c5248498a866672d85eca0a0f5 Size/MD5 checksum: 730722 1b0750ba641b4ccbb1926e1446bbc9eb Size/MD5 checksum: 205764 56d117733da1be89fd8525d491c95a16 Size/MD5 checksum: 33084 d31c892ef95d30f0f8359df61b0481f4 Size/MD5 checksum: 170504 4a0acca19f8752621874046503a3f9df HP Precision architecture: Size/MD5 checksum: 93242 1679b3c9cf120b5b56d883cead2f544f Size/MD5 checksum: 101232 7e5c1f2c3885fea8f87f9fec1028b888 Size/MD5 checksum: 64986 55bd18e636b2485314120388d3ed4a73 Size/MD5 checksum: 270922 e7f5050518729caa3ae6925227f023ab Size/MD5 checksum: 505386 84e47f0d34928923f2c2e0ae1ccf5487 Size/MD5 checksum: 146200 ebb3cd2ddf9afcfa113d1b0d60dd256e Size/MD5 checksum: 93228 6a20a730277fa505d4e27495fd4b3424 Size/MD5 checksum: 250216 f42a8d0d6d594a601a362ea0f738b185 Size/MD5 checksum: 146362 b3529d2098e96ed4f19d31d17865c2e2 Size/MD5 checksum: 246034 32b469be4a18a7cfe1c9a65aead8a533 Size/MD5 checksum: 796926 8c3f9a89fc543ec69a12a659c7dcfbe3 Size/MD5 checksum: 757492 478d712e3bade83d527140c8fa2821e8 Size/MD5 checksum: 535250 f726eb1a2a2705c84c48bbf1abd268ab Size/MD5 checksum: 2371576 8ac6f9581c28c9252eac55ed6c09385a Size/MD5 checksum: 61422 8d6b0374dea1c1efb042fc5e5edcf0c7 Size/MD5 checksum: 99192 2aad4f1b8942ade1bb889a2ee10746b0 Size/MD5 checksum: 1563008 a8203d54a3f59af2739fb75d6cd90049 Size/MD5 checksum: 485056 918c0d745609e787bc58de530c6abaff Size/MD5 checksum: 700886 4c84103b7cea6763a57fa608e094c69e Size/MD5 checksum: 183850 a03abfea16b0a0946221d473ddd796ae Size/MD5 checksum: 33092 7ba9eb3e7b707decced38a098b067e26 Size/MD5 checksum: 148004 90d49f8cef0520eb1c022918dd429a99 Motorola 680x0architecture: Size/MD5 checksum: 85370 03208de88212ee8e3c433c6c69673877 Size/MD5 checksum: 91096 b75db8b3d6a30dd952ae78758510b296 Size/MD5 checksum: 65010 82d5536cd79f3bac8a4b483e5571eb23 Size/MD5 checksum: 229546 7b682eb8db73e63407bff2b29f6ffb4c Size/MD5 checksum: 476952 fe27e5395f5ea231f77dd1abbb74c7e5 Size/MD5 checksum: 138540 acfa677ff78e256cd8e085cf75d16d97 Size/MD5 checksum: 85196 988a2fdd5de86648a524b8dec7173ea9 Size/MD5 checksum: 229420 9c328ece393d69c84db7304c8260fdb5 Size/MD5 checksum: 128626 7e1f68605fc327a146fc851894004ead Size/MD5 checksum: 223556 941a4f007761da9124029e68431fff9f Size/MD5 checksum: 705084 2439ec0bc20dd2c60022ead6b118ab5e Size/MD5 checksum: 743170 832c8961b239bcf874a90c5ac3fd14f1 Size/MD5 checksum: 447448 c38dcc1879650cd3bcdae5484631c281 Size/MD5 checksum: 2148768 0148565136745e0309b056cfdc77874e Size/MD5 checksum: 61280 cd7c09ba73c52e33d77a277833c28c24 Size/MD5 checksum: 96636 a1d244a87142ca153826f09623196b4b Size/MD5 checksum: 1315968 b3dbc843325ecc8b4f23dfbdbd04da35 Size/MD5 checksum: 475814 5adbdb5ea44cc6e774d06269f0123014 Size/MD5 checksum: 682572 22deaf8ff281062b43f45a50e8e52c53 Size/MD5 checksum: 166284 c772a82c000c4faed889bc1572907198 Size/MD5 checksum: 33100 117362ae11ee0926fe62d4251e45b9c8 Size/MD5 checksum: 133970 cc9320ce6077055fbef7f357baccb36b Big endian MIPS architecture: Size/MD5 checksum: 79726 8ef8a7f51e426bab0c79c893b17b44e8 Size/MD5 checksum: 102528 96063761ffb299e8663aabdc1dc830dc Size/MD5 checksum: 64974 8632642c61fd3e514d79c53c440b0157 Size/MD5 checksum: 217900 9f068d5736f65a59d58843ef3719914a Size/MD5 checksum: 461010 44d402c815ef59102a9d1f6a1922e5c7 Size/MD5 checksum: 1405125dede51b9875eb9627fe84508f3ff4cc Size/MD5 checksum: 81838 109efab6c00ef662a00ea4f41e7a0069 Size/MD5 checksum: 215748 ad22b37ce1d1ffef16c7cefde0ffd7d5 Size/MD5 checksum: 146198 b9c2cba23d25f1bf3bdbbdbeaffeadbd Size/MD5 checksum: 204014 83a4764d81ef5ee7fd7fe890e23c9939 Size/MD5 checksum: 787984 c020ab67521dcaca8e49c0bae8216b28 Size/MD5 checksum: 756170 a1d1e3e06e5eed39f29d03ce572d5771 Size/MD5 checksum: 455814 8b5479eb17b3ea84f56d35f3d1992b43 Size/MD5 checksum: 2057362 71d2689d1981f83a6f8ff468d69cc0ce Size/MD5 checksum: 59274 1cf3d865852bbb4965229a95c78a52b1 Size/MD5 checksum: 97718 1e697e2bf6d19eb71efe3350e63a8ddc Size/MD5 checksum: 1127026 0bc2eab83b2cc242ecaebba694289235 Size/MD5 checksum: 463634 9bee129653701a27a392f118c2e2fc28 Size/MD5 checksum: 649718 dfa1146d95d54eab9f51301b5f4a28eb Size/MD5 checksum: 156802 9126d5152c28c24889e5269a9adde39f Size/MD5 checksum: 33094 9875a23d1590f9016f8a8bb450bf3a6d Size/MD5 checksum: 124558 eb55d58484f5ecdc59b2c6eb3c47a805 Little endian MIPS architecture: Size/MD5 checksum: 79070 ea21445ae1aef174831e9534db959308 Size/MD5 checksum: 101596 ed6adfa04d7c4c2c4d002cb5a278583f Size/MD5 checksum: 64972 434438d23e8b0ccc9c38dcc699164e53 Size/MD5 checksum: 215850 82f87ff8b5520823f839092cef2356b0 Size/MD5 checksum: 459624 e577a100b76fe42784b6dcc35f5046b6 Size/MD5 checksum: 139548 4e829465b219a4d56b86b687b33d5df0 Size/MD5 checksum: 81370 937ce8392adf141a1f79af0dfc80e499 Size/MD5 checksum: 213272 bf8c38a0afb9c9f966cd00bc42a4d4c0 Size/MD5 checksum: 144554 ca97a5ce320d502c908580bf0bcc4033 Size/MD5 checksum: 201638 45e29afdb0ab123d149a739520f1c32c Size/MD5 checksum: 785228 9902604485b4e9633f3e36f01fc8f920 Size/MD5 checksum: 754276 b1be56ab0f23c02f6aa29b1276a3d917 Size/MD5 checksum: 446852 99ac862679028515f5f715c047719e2f Size/MD5 checksum: 2046016 8c9919a529a79538629221bf98e37b61 Size/MD5 checksum: 59068 5c2aad04a5f5265034faca5d8fd82c64 Size/MD5 checksum: 97168 498f72e93b50faefb22a9ca9335193a1 Size/MD5 checksum: 1101768 8cb8b46c5207d06911d77d3178f9a4f8 Size/MD5 checksum: 461868 4792dcccbb8fcda14f2eb601692e2c01 Size/MD5 checksum: 647264 9a340b39b3b2ce04d2ed0cfe240bca8b Size/MD5 checksum: 154678 79ac08fbe101be7efe6e3471d5fb787d Size/MD5 checksum: 33100 3c5ab7cfcd4fce969cd6066c9a9b31d9 Size/MD5 checksum: 122404 3d2878bbacb4862c25b73d6c71a6f649 PowerPC architecture: Size/MD5 checksum: 84678 c40175b83c13941983dd07e2ec17bdda Size/MD5 checksum: 94604 720a71fb1d61f0f16a919926a996ebb8 Size/MD5 checksum: 64990 6b4a44cd20244525cf7ed61ef63da641 Size/MD5 checksum: 249552 78b554c699af127b69b39b49ac4c180b Size/MD5 checksum: 474624 b38b81bf2974e7d72095eb84b00de64d Size/MD5 checksum: 140692 cfb9009df7900bfbfdbc39f7523fc587 Size/MD5 checksum: 85162 130665aee67bc16e9be3ca54a3762862 Size/MD5 checksum: 224802 60d742b0d2303bc63b1849dae1397581 Size/MD5 checksum: 132544 6f6bd6ab29fcbf3311f1015a35aec78f Size/MD5 checksum: 222198 993f41bfbccf6481ca327f2e8dc3c20d Size/MD5 checksum: 725370 0f9836476933dbe813ea538c5d052cd8 Size/MD5 checksum: 744166 608091d9c9b27dde512ac47b6947d626 Size/MD5 checksum: 467524 46073d588f362de378386698c39c95c7 Size/MD5 checksum: 2142348 9e3bfa19052e85058e4fa31a6298f0a0 Size/MD5 checksum: 61046 b4d834e88473d8776d305e0448ebe476 Size/MD5 checksum: 95544 977ad02f98bcf9731dc2fca1ad1eebc5 Size/MD5 checksum: 1191074 8fb34b60f7d2fb4484da19634fb83ca2 Size/MD5 checksum: 470198 4b8539d72cc39d7e1939f526c765c8b7 Size/MD5 checksum: 676288 94b7d619e9eb8ecd0cfb0bb3be8ae4ba Size/MD5 checksum: 161756 d59119ba3140c9e41aaafc0c16af7c63 Size/MD5 checksum: 33098 980dc1cabb51360efe73cb00e37b3ae1 Size/MD5 checksum: 132262 66496d5de6353b80c647b32f4c18ef8b IBM S/390 architecture: Size/MD5 checksum: 89880 99dff2d06524836ab720abd471999d66 Size/MD5 checksum: 98316 893cdc7754cae8a00ee116fcdbf9fb73 Size/MD5 checksum: 64972 bd908c097ca775f368b3b87db83ada06 Size/MD5 checksum: 236504 603bbb604f6cf907a31b29e8c0438351 Size/MD5 checksum: 484950 957eae05f1920388664d5db6b42ae80f Size/MD5 checksum: 145404 061c37b7acbe75a09bc6a983e24eca22 Size/MD5 checksum: 87136 4c9745eccb44c21a609b5ffaf768a26a Size/MD5 checksum: 244122 9b7d68631bccc0af9b79214ec7d3e8d5 Size/MD5 checksum: 140834 3230bfe76d926783b336e0b424685896 Size/MD5 checksum: 239688 42a8e7956bfd756ffba9e7bcd5314e8c Size/MD5 checksum: 765928 3a38ceb3563211404e5534bc691b887c Size/MD5 checksum: 755596 40d810e17c05d8ff21d76550c0e5cc3a Size/MD5 checksum: 496480 0a48f1beb7a4e03425783a909bc88ef0 Size/MD5 checksum: 2195656 c26f4c732fe8393766eccff6a845e938 Size/MD5 checksum: 63070 ea7b94304194ffa4d0bbd708f84737db Size/MD5 checksum: 100742 b5f3558b9d1e30038dabbf0f4b0ba36f Size/MD5 checksum: 1192548 db812a33636b9a681083895da654d9ac Size/MD5 checksum: 481678 93c6f759b0cc1965dbb93536dc255dac Size/MD5 checksum: 682752 519c3b25389f72155e005e12a6989972 Size/MD5 checksum: 176666 194c2424523d195373e0d4177b2c1ded Size/MD5 checksum: 33090 8882749212a6e977b9eec3e9fb595f50 Size/MD5 checksum: 142212 c95e8e7fe4365be445daead6d366c5ac Sun Sparc architecture: Size/MD5 checksum: 82296 25f2b504c0cc096508d2565f38db6f28 Size/MD5 checksum: 90720 d8a9ee57d67676bdd2637a40b941b8cb Size/MD5 checksum: 64980 967f32d4dc6fc6f5d9ff4ef838bae770 Size/MD5 checksum: 219164 141a05361d233b94f81be5a802de14d9 Size/MD5 checksum: 477510 e71886db4ca53b2c23f421857844dc35 Size/MD5 checksum: 137938 22442ddae2f20c3663c270541e9ba9c1 Size/MD5 checksum: 83210 abfc0612516de6079f6552f0dae1743f Size/MD5 checksum: 223774 3b242e3415e216278bd5922d09cafa73 Size/MD5 checksum: 130520 171569986b9d5f75037fac7216f51014 Size/MD5 checksum: 213588 25bdfc45123cbcac842c5c01882c9551 Size/MD5 checksum: 714158 a4ba5b48aec9eaf736315dee410a53bc Size/MD5 checksum: 744042 5894e3e97fc45d024219a9ff7e115854 Size/MD5 checksum: 451392 de85d22d0d458866bdffba846d4accc2 Size/MD5 checksum: 2142550 732f1d703ab5d8bba7345e50db66283c Size/MD5 checksum: 60184 012973b512f9bdfbf15830812fc2b863 Size/MD5 checksum: 95092 766c1952f778a25f2aab9bd20964a676 Size/MD5 checksum: 1175232 7398855b8444740ce27001c427544406 Size/MD5 checksum: 469204 b2e9d809bfc831938f3d080990b7efae Size/MD5 checksum: 639718 6054b8e3f4c9142551a7fd114cb71bb6 Size/MD5 checksum: 160294 c47394d5c4923c4a921fd400a8f107a0 Size/MD5 checksum: 33090 84d007d379333f73de214d1af530ea8d Size/MD5 checksum: 128730 ef6ffca3dd504cd20953e7b5c0775014 These files will probably be moved into the stable distribution on its next update. - ---------------------------------------------------------------------------------For apt-get: deb https://www.debian.org/security/ stable/updates main For dpkg-ftp: dists/stable/updates/main Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Debian Security Advisory DSA 932-1 http://www.debian.org/security/ Martin Schulze January 9th, 2006 . infamous41md', chris, evans, based, buffer, overflows, portable. . Severity:Critical. LinuxSecurity.com Team

Calendar 2 Jan 27, 2006 Critical Debian
91

Gentoo: GLSA-200508-08 Normal: Xpdf, Kpdf, GPdf DoS Threat

Xpdf, Kpdf and GPdf may crash as a result of a Denial of Service vulnerability.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200508-08 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: Xpdf, Kpdf, GPdf: Denial of Service vulnerability Date: August 16, 2005 Bugs: #99769, #100263, #100265 ID: 200508-08 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= Xpdf, Kpdf and GPdf may crash as a result of a Denial of Service vulnerability. Background ========= Xpdf, Kpdf and GPdf are PDF file viewers that run under the X Window System. Kpdf and GPdf both contain Xpdf code. Kpdf is also part of kdegraphics. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 app-text/xpdf < 3.00-r10 > = 3.00-r10 2 kde-base/kdegraphics < 3.3.2-r3 > = 3.3.2-r3 3 kde-base/kpdf < 3.4.1-r1 > = 3.4.1-r1 4 app-text/gpdf < 2.10.0-r1 > = 2.10.0-r1 ------------------------------------------------------------------- 4 affected packages on all of their supported architectures. ------------------------------------------------------------------- Description ========== Xpdf, Kpdf and GPdf do not handle a broken table of embedded TrueType fonts correctly. After detecting such a table, Xpdf, Kpdf and GPdf attempt to reconstruct the information in it by decoding the PDF file, which causes the generation of a huge temporary file. Impact ===== A remote attacker may cause a Denial ofService by creating a specially crafted PDF file, sending it to a CUPS printing system (which uses Xpdf), or by enticing a user to open it in Xpdf, Kpdf, or GPdf. Workaround ========= There is no known workaround at this time. Resolution ========= All Xpdf users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =app-text/xpdf-3.00-r10" All GPdf users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =app-text/gpdf-2.10.0-r1" All Kpdf users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =kde-base/kdegraphics-3.3.2-r3" All KDE Split Ebuild Kpdf users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =kde-base/kpdf-3.4.1-r1" References ========= [ 1 ] CAN-2005-2097 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/200508-08 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users machines is of utmost importance to us. Any security concerns should be addressed to This email address is being protected from spambots. You need JavaScript enabled to view it. or alternatively, you may file a bug at https://bugs.gentoo.org/. License ====== Copyright 2005 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. https://creativecommons.org/licenses/by-sa/2.0/ . Users of Xpdf, Kpdf, and GPdf are strongly encouraged to update their software in response to a critical Denial of Service attack flaw discovered in these PDF readers.. Xpdf Denial of Service,Kpdf Security Update,GPdf Vulnerability. . LinuxSecurity.com Team

Calendar 2 Aug 16, 2005 Gentoo
98

Red Hat: RHSA-2005:671-01 Moderate: kpdf Denial of Service

Updated kdegraphics packages that resolve a security issue in kpdf are now available. This update has been rated as having moderate security impact by the Red Hat Security Response Team.. - --------------------------------------------------------------------- Red Hat Security Advisory Synopsis: Moderate: kdegraphics security update Advisory ID: RHSA-2005:671-01 Advisory URL: https://access.redhat.com/errata/RHSA-2005:671.html Issue date: 2005-08-09 Updated on: 2005-08-09 Product: Red Hat Enterprise Linux CVE Names: CAN-2005-2097 - ---------------------------------------------------------------------1. Summary: Updated kdegraphics packages that resolve a security issue in kpdf are now available. This update has been rated as having moderate security impact by the Red Hat Security Response Team. 2. Relevant releases/architectures: Red Hat Enterprise Linux AS version 4 - i386, ia64, ppc, s390, s390x, x86_64 Red Hat Enterprise Linux Desktop version 4 - i386, x86_64 Red Hat Enterprise Linux ES version 4 - i386, ia64, x86_64 Red Hat Enterprise Linux WS version 4 - i386, ia64, x86_64 3. Problem description: The kdegraphics packages contain applications for the K Desktop Environment including kpdf, a pdf file viewer. A flaw was discovered in kpdf. An attacker could construct a carefully crafted PDF file that would cause kpdf to consume all available disk space in /tmp when opened. The Common Vulnerabilities and Exposures project assigned the name CAN-2005-2097 to this issue. Note this issue does not affect Red Hat Enterprise Linux 3 or 2.1. Users of kpdf should upgrade to these updated packages, which contains a backported patch to resolve this issue. 4. Solution: Before applying this update, make sure that all previously-released errata relevant to your system have been applied. Use Red Hat Network to download and update your packages. To launch the Red Hat Update Agent, use the followingcommand: up2date For information on how to install packages manually, refer to the following Web page for the System Administration or Customization guide specific to your system: https://docs.redhat.com/en/documentation/red_hat_enterprise_linux/10/ 5. Bug IDs fixed (http://bugzilla.redhat.com/): 163925 - CAN-2005-2097 kpdf DoS 6. RPMs required: Red Hat Enterprise Linux AS version 4: SRPMS: 034c8c6c6f6b306170dd84943f4caebf kdegraphics-3.3.1-3.4.src.rpm i386: 551912cff4672ac8e5d8c9e1c1aa6bd5 kdegraphics-3.3.1-3.4.i386.rpm 7d26d5de1c406e6e89333eb17c4d9720 kdegraphics-devel-3.3.1-3.4.i386.rpm ia64: c26447459cac09d0b8a680f8aff37cce kdegraphics-3.3.1-3.4.ia64.rpm 1072f640b595f512ba217264d2c77aec kdegraphics-devel-3.3.1-3.4.ia64.rpm ppc: 5f05c498a6515ea03b567691a1795588 kdegraphics-3.3.1-3.4.ppc.rpm 12f3c69ef13a8617ef6e3c3ef7108b6f kdegraphics-devel-3.3.1-3.4.ppc.rpm s390: 6492a12dd82ab6ad78977b36f6acc277 kdegraphics-3.3.1-3.4.s390.rpm 644af9b7f094d9fad6eb43423b04854a kdegraphics-devel-3.3.1-3.4.s390.rpm s390x: 8a8e96eacc5ebff6f6cb9d4d0f87b229 kdegraphics-3.3.1-3.4.s390x.rpm 6a83d580fe2d065f1f2cff4978c00ec5 kdegraphics-devel-3.3.1-3.4.s390x.rpm x86_64: ff88d2ce2b9129ba3cc8f0b90d8350cc kdegraphics-3.3.1-3.4.x86_64.rpm 4e67a2cb74e2dbd7d264c2967ade9f97 kdegraphics-devel-3.3.1-3.4.x86_64.rpm Red Hat Enterprise Linux Desktop version 4: SRPMS: 034c8c6c6f6b306170dd84943f4caebf kdegraphics-3.3.1-3.4.src.rpm i386: 551912cff4672ac8e5d8c9e1c1aa6bd5 kdegraphics-3.3.1-3.4.i386.rpm 7d26d5de1c406e6e89333eb17c4d9720 kdegraphics-devel-3.3.1-3.4.i386.rpm x86_64: ff88d2ce2b9129ba3cc8f0b90d8350cc kdegraphics-3.3.1-3.4.x86_64.rpm 4e67a2cb74e2dbd7d264c2967ade9f97 kdegraphics-devel-3.3.1-3.4.x86_64.rpm Red Hat Enterprise Linux ES version 4: SRPMS: 034c8c6c6f6b306170dd84943f4caebf kdegraphics-3.3.1-3.4.src.rpm i386: 551912cff4672ac8e5d8c9e1c1aa6bd5 kdegraphics-3.3.1-3.4.i386.rpm 7d26d5de1c406e6e89333eb17c4d9720 kdegraphics-devel-3.3.1-3.4.i386.rpm ia64: c26447459cac09d0b8a680f8aff37cce kdegraphics-3.3.1-3.4.ia64.rpm 1072f640b595f512ba217264d2c77aec kdegraphics-devel-3.3.1-3.4.ia64.rpm x86_64: ff88d2ce2b9129ba3cc8f0b90d8350cc kdegraphics-3.3.1-3.4.x86_64.rpm 4e67a2cb74e2dbd7d264c2967ade9f97 kdegraphics-devel-3.3.1-3.4.x86_64.rpm Red Hat Enterprise Linux WS version 4: SRPMS: 034c8c6c6f6b306170dd84943f4caebf kdegraphics-3.3.1-3.4.src.rpm i386: 551912cff4672ac8e5d8c9e1c1aa6bd5 kdegraphics-3.3.1-3.4.i386.rpm 7d26d5de1c406e6e89333eb17c4d9720 kdegraphics-devel-3.3.1-3.4.i386.rpm ia64: c26447459cac09d0b8a680f8aff37cce kdegraphics-3.3.1-3.4.ia64.rpm 1072f640b595f512ba217264d2c77aec kdegraphics-devel-3.3.1-3.4.ia64.rpm x86_64: ff88d2ce2b9129ba3cc8f0b90d8350cc kdegraphics-3.3.1-3.4.x86_64.rpm 4e67a2cb74e2dbd7d264c2967ade9f97 kdegraphics-devel-3.3.1-3.4.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key#package 7. References: https://www.cve.org/CVERecord?id=CAN-2005-2097 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2005 Red Hat, Inc. . The recent update for kdegraphics addresses a moderate security vulnerability affecting Red Hat systems, enhancing the safety of PDF processing within kpdf.. Kdegraphics Security Update, Red Hat Advisory, Moderate Risk Fix, kpdf Patch. . LinuxSecurity.com Team

Calendar 2 Aug 09, 2005 Red Hat
91

Gentoo: GLSA-200501-17 Normal: KPdf KOffice Code Execution Risk

KPdf and KOffice both include vulnerable Xpdf code to handle PDF files, making them vulnerable to the execution of arbitrary code if a user is enticed to view a malicious PDF file. [More...]. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200501-17 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: KPdf, KOffice: More vulnerabilities in included Xpdf Date: January 11, 2005 Bugs: #75203, #75204 ID: 200501-17 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= KPdf and KOffice both include vulnerable Xpdf code to handle PDF files, making them vulnerable to the execution of arbitrary code if a user is enticed to view a malicious PDF file. Background ========= KPdf is a KDE-based PDF viewer included in the kdegraphics package. KOffice is an integrated office suite for KDE. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 app-office/koffice < 1.3.5-r1 > = 1.3.5-r1 2 kde-base/kdegraphics < 3.3.2-r1 > = 3.3.2-r1 *> = 3.2.3-r3 ------------------------------------------------------------------- 2 affected packages on all of their supported architectures. ------------------------------------------------------------------- Description ========== KPdf and KOffice both include Xpdf code to handle PDF files. Xpdf is vulnerable to multiple new integer overflows, as described in GLSA 200412-24. Impact ===== An attacker could entice a user to open aspecially-crafted PDF file, potentially resulting in the execution of arbitrary code with the rights of the user running the affected utility. Workaround ========= There is no known workaround at this time. Resolution ========= All KPdf users should upgrade to the latest version of kdegraphics: # emerge --sync # emerge --ask --oneshot --verbose kde-base/kdegraphics Note: There is currently no fixed stable 3.3.x version for sparc. All KOffice users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose app-office/koffice References ========= [ 1 ] GLSA 200412-24 https://security.gentoo.org/glsa/200412-24 [ 2 ] CAN-2004-1125 https://www.cve.org/CVERecord?id=CVE-CAN-2004-1125 [ 3 ] KDE Security Advisory: kpdf Buffer Overflow Vulnerability https://kde.org/info/security/advisory-20041223-1.txt [ 4 ] KOffice XPDF Integer Overflow 2 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/200501-17 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users machines is of utmost importance to us. Any security concerns should be addressed to This email address is being protected from spambots. You need JavaScript enabled to view it. or alternatively, you may file a bug at https://bugs.gentoo.org/. License ====== Copyright 2005 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. https://creativecommons.org/licenses/by-sa/2.0/ . Gentoo GLSA 202302-10 highlights security flaws in LibreOffice stemming from outdated encryption libraries. Immediate update recommended.. KPdf Vulnerability,KOffice Update,Gentoo Security Advisory,Xpdf Security Issue,Code Execution Risk. . LinuxSecurity.com Team

Calendar 2 Jan 11, 2005 Gentoo
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here