security advisorycode executiongpdf
Important: gpdf security update. Date: Thu, 7 Oct 2010 15:37:50 -0500 Reply-To: Troy Dawson Sender: Security Errata for Scientific Linux From: Troy Dawson Subject: Security ERRATA Important: gpdf on SL4.x i386/x86_64 Comments: To: "This email address is being protected from spambots. You need JavaScript enabled to view it." Synopsis: Important: gpdf security update Issue date: 2010-10-07 CVE Names: CVE-2010-3702 CVE-2010-3704 An uninitialized pointer use flaw was discovered in GPdf. An attacker could create a malicious PDF file that, when opened, would cause GPdf to crash or, potentially, execute arbitrary code. (CVE-2010-3702) An array index error was found in the way GPdf parsed PostScript Type 1 fonts embedded in PDF documents. An attacker could create a malicious PDF file that, when opened, would cause GPdf to crash or, potentially, execute arbitrary code. (CVE-2010-3704) SL 4.x SRPMS: gpdf-2.8.2-7.7.2.el4_8.7.src.rpm i386: gpdf-2.8.2-7.7.2.el4_8.7.i386.rpm x86_64: gpdf-2.8.2-7.7.2.el4_8.7.x86_64.rpm -Connie Sieh -Troy Dawson . Crucial gpdf security patch for Scientific Linux addresses vulnerabilities that could lead to system failures and unauthorized code execution via harmful PDF files.. gpdf security update, Scientific Linux, PDF exploit, important patch. . Severity: Important. LinuxSecurity.com Team
Oct 07, 2010
•Important
Scientific Linux