Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
CVE-2021-3407. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2021-baeaa7bccb 2021-03-19 19:51:22.362122 --------------------------------------------------------------------------------Name : mupdf Product : Fedora 34 Version : 1.18.0 Release : 6.fc34 URL : https://mupdf.com/ Summary : A lightweight PDF viewer and toolkit Description : MuPDF is a lightweight PDF viewer and toolkit written in portable C. The renderer in MuPDF is tailored for high quality anti-aliased graphics. MuPDF renders text with metrics and spacing accurate to within fractions of a pixel for the highest fidelity in reproducing the look of a printed page on screen. MuPDF has a small footprint. A binary that includes the standard Roman fonts is only one megabyte. A build with full CJK support (including an Asian font) is approximately five megabytes. MuPDF has support for all non-interactive PDF 1.7 features, and the toolkit provides a simple API for accessing the internal structures of the PDF document. Example code for navigating interactive links and bookmarks, encrypting PDF files, extracting fonts, images, and searchable text, and rendering pages to image files is provided. --------------------------------------------------------------------------------Update Information: CVE-2021-3407 --------------------------------------------------------------------------------ChangeLog: * Wed Feb 24 2021 Michael J Gruber - 1.18.0-6 - remove obsolete PyMuPDF support * Tue Feb 23 2021 Michael J Gruber - 1.18.0-5 - CVE-2021-3407 (bz #1931964, bz#1931965) --------------------------------------------------------------------------------References: [ 1 ] Bug #1931964 - CVE-2021-3407 mupdf: Double free of object during linearization https://bugzilla.redhat.com/show_bug.cgi?id=1931964 --------------------------------------------------------------------------------This update can be installed with the"dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2021-baeaa7bccb' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
CVE-2021-3407. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2021-d8e6f014e5 2021-03-05 19:23:15.233222 --------------------------------------------------------------------------------Name : mupdf Product : Fedora 32 Version : 1.18.0 Release : 5.fc32 URL : https://mupdf.com/ Summary : A lightweight PDF viewer and toolkit Description : MuPDF is a lightweight PDF viewer and toolkit written in portable C. The renderer in MuPDF is tailored for high quality anti-aliased graphics. MuPDF renders text with metrics and spacing accurate to within fractions of a pixel for the highest fidelity in reproducing the look of a printed page on screen. MuPDF has a small footprint. A binary that includes the standard Roman fonts is only one megabyte. A build with full CJK support (including an Asian font) is approximately five megabytes. MuPDF has support for all non-interactive PDF 1.7 features, and the toolkit provides a simple API for accessing the internal structures of the PDF document. Example code for navigating interactive links and bookmarks, encrypting PDF files, extracting fonts, images, and searchable text, and rendering pages to image files is provided. --------------------------------------------------------------------------------Update Information: CVE-2021-3407 --------------------------------------------------------------------------------ChangeLog: * Tue Feb 23 2021 Michael J Gruber - 1.18.0-5 - CVE-2021-3407 (bz #1931964, bz#1931965) * Tue Jan 26 2021 Michael J Gruber - 1.18.0-4 - (original date: Thu Oct 29 2020) - remove obsolete patch * Tue Jan 26 2021 Fedora Release Engineering - 1.18.0-3 - Rebuilt for https://fedoraproject.org/wiki/Fedora_34_Mass_Rebuild --------------------------------------------------------------------------------References: [ 1 ] Bug #1931964 - CVE-2021-3407 mupdf: Double free of object during linearization https://bugzilla.redhat.com/show_bug.cgi?id=1931964 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2021-d8e6f014e5' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Update to 4.03. Fixes CVE-2020-35376 and CVE-2020-25725.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2021-4a437fe032 2021-02-11 01:52:12.933144 --------------------------------------------------------------------------------Name : xpdf Product : Fedora 32 Version : 4.03 Release : 1.fc32 URL : http://www.xpdfreader.com/ Summary : A PDF file viewer for the X Window System Description : Xpdf is an X Window System based viewer for Portable Document Format (PDF) files. Xpdf is a small and efficient program which uses standard X fonts. --------------------------------------------------------------------------------Update Information: Update to 4.03. Fixes CVE-2020-35376 and CVE-2020-25725. --------------------------------------------------------------------------------ChangeLog: * Tue Feb 2 2021 Tom Callaway - 1:4.03-1 - update to 4.03 * Thu Jan 28 2021 Fedora Release Engineering - 1:4.02-6 - Rebuilt for https://fedoraproject.org/wiki/Fedora_34_Mass_Rebuild * Wed Jul 29 2020 Fedora Release Engineering - 1:4.02-5 - Rebuilt for https://fedoraproject.org/wiki/Fedora_33_Mass_Rebuild --------------------------------------------------------------------------------References: [ 1 ] Bug #1899520 - CVE-2020-25725 xpdf: sending crafted a PDF document to the pdftops tool could result in DoS https://bugzilla.redhat.com/show_bug.cgi?id=1899520 [ 2 ] Bug #1911349 - CVE-2020-35376 xpdf: stack consumption due to an incorrect subroutine reference in a Type 1C font charstring https://bugzilla.redhat.com/show_bug.cgi?id=1911349 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2021-4a437fe032' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html Allpackages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Several minor issues have been fixed in mupdf, a lightweight PDF viewer tailored for display of high quality anti-aliased graphics. . Package : mupdf Version : 1.5-1+deb8u6 CVE ID : CVE-2018-5686 CVE-2019-6130 CVE-2018-6192 Debian Bug : 887130 888487 918971 Several minor issues have been fixed in mupdf, a lightweight PDF viewer tailored for display of high quality anti-aliased graphics. CVE-2018-5686 In MuPDF, there was an infinite loop vulnerability and application hang in the pdf_parse_array function (pdf/pdf-parse.c) because EOF not having been considered. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted PDF file. CVE-2019-6130 MuPDF had a SEGV in the function fz_load_page of the fitz/document.c file, as demonstrated by mutool. This was related to page-number mishandling in cbz/mucbz.c, cbz/muimg.c, and svg/svg-doc.c. CVE-2018-6192 In MuPDF, the pdf_read_new_xref function in pdf/pdf-xref.c allowed remote attackers to cause a denial of service (segmentation violation and application crash) via a crafted PDF file. For Debian 8 "Jessie", these problems have been fixed in version 1.5-1+deb8u6. We recommend that you upgrade your mupdf packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS -- mike gabriel aka sunweaver (Debian Developer) fon: +49 (1520) 1976 148 GnuPG Fingerprint: 9BFB AEE8 6C0A A5FF BF22 0782 9AF4 6B30 2577 1B31 mail:
New release (1.10a). Security fix for CVE-2016-6265. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2017-6fe982684d 2017-02-28 19:57:20.625579 -------------------------------------------------------------------------------- Name : mupdf Product : Fedora 25 Version : 1.10a Release : 1.fc25 URL : https://mupdf.com/ Summary : A lightweight PDF viewer and toolkit Description : MuPDF is a lightweight PDF viewer and toolkit written in portable C. The renderer in MuPDF is tailored for high quality anti-aliased graphics. MuPDF renders text with metrics and spacing accurate to within fractions of a pixel for the highest fidelity in reproducing the look of a printed page on screen. MuPDF has a small footprint. A binary that includes the standard Roman fonts is only one megabyte. A build with full CJK support (including an Asian font) is approximately five megabytes. MuPDF has support for all non-interactive PDF 1.7 features, and the toolkit provides a simple API for accessing the internal structures of the PDF document. Example code for navigating interactive links and bookmarks, encrypting PDF files, extracting fonts, images, and searchable text, and rendering pages to image files is provided. -------------------------------------------------------------------------------- Update Information: New release (1.10a). Security fix for CVE-2016-6265 -------------------------------------------------------------------------------- References: [ 1 ] Bug #1359108 - CVE-2016-6265 mupdf: Use after free vulnerability in pdf_xref.c https://bugzilla.redhat.com/show_bug.cgi?id=1359108 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade mupdf' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signedwith the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
Updated package.. - --------------------------------------------------------------------------Debian Security Advisory DSA 982-1
Updated kdegraphics packages that resolve a security issue in kpdf are now available. This update has been rated as having important security impact by the Red Hat Security Response Team.. - --------------------------------------------------------------------- Red Hat Security Advisory Synopsis: Important: kdegraphics security update Advisory ID: RHSA-2006:0206-01 Advisory URL: https://access.redhat.com/errata/RHSA-2006:0206.html Issue date: 2006-02-13 Updated on: 2006-02-13 Product: Red Hat Enterprise Linux CVE Names: CVE-2006-0301 - ---------------------------------------------------------------------1. Summary: Updated kdegraphics packages that resolve a security issue in kpdf are now available. This update has been rated as having important security impact by the Red Hat Security Response Team. 2. Relevant releases/architectures: Red Hat Enterprise Linux AS version 4 - i386, ia64, ppc, s390, s390x, x86_64 Red Hat Enterprise Linux Desktop version 4 - i386, x86_64 Red Hat Enterprise Linux ES version 4 - i386, ia64, x86_64 Red Hat Enterprise Linux WS version 4 - i386, ia64, x86_64 3. Problem description: The kdegraphics packages contain applications for the K Desktop Environment including kpdf, a pdf file viewer. A heap based buffer overflow bug was discovered in kpdf. An attacker could construct a carefully crafted PDF file that could cause kpdf to crash or possibly execute arbitrary code when opened. The Common Vulnerabilities and Exposures project assigned the name CVE-2006-0301 to this issue. Users of kpdf should upgrade to these updated packages, which contain a backported patch to resolve this issue. 4. Solution: Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via Red Hat Network. To use Red Hat Network, launch the Red Hat Update Agent with the following command: up2date This willstart an interactive process that will result in the appropriate RPMs being upgraded on your system. 5. Bug IDs fixed (http://bugzilla.redhat.com/): 179055 - CVE-2006-0301 PDF splash handling heap overflow 6. RPMs required: Red Hat Enterprise Linux AS version 4: SRPMS: 90ac8bd5592b058f6eb37df331008226 kdegraphics-3.3.1-3.7.src.rpm i386: aeec5e4c97d1ccabf1e52036bb37ca79 kdegraphics-3.3.1-3.7.i386.rpm f48caa317d180ee1b40667c62df4acb6 kdegraphics-devel-3.3.1-3.7.i386.rpm ia64: 3d3b3279d047bfff9cd14271072bd443 kdegraphics-3.3.1-3.7.ia64.rpm 432dea1108d258f6af3964180ab4d179 kdegraphics-devel-3.3.1-3.7.ia64.rpm ppc: 7ee2305e63d0e6fe38bdec4a0a5f9326 kdegraphics-3.3.1-3.7.ppc.rpm 092a795864d53d21144289a92fc33b01 kdegraphics-devel-3.3.1-3.7.ppc.rpm s390: ef808523b180cccfdbcec51f9a020ee8 kdegraphics-3.3.1-3.7.s390.rpm 278dd2949ff7f09eb3b5018fa97cc75f kdegraphics-devel-3.3.1-3.7.s390.rpm s390x: 71f7124916aeb01b793f54f2d85312b6 kdegraphics-3.3.1-3.7.s390x.rpm 9863edc3e66f3bd825cdd34df93e1b00 kdegraphics-devel-3.3.1-3.7.s390x.rpm x86_64: 37cf516a06d3f42159ce54c62b901794 kdegraphics-3.3.1-3.7.x86_64.rpm 9b65bf232f163136cf5db28fd82fc661 kdegraphics-devel-3.3.1-3.7.x86_64.rpm Red Hat Enterprise Linux Desktop version 4: SRPMS: 90ac8bd5592b058f6eb37df331008226 kdegraphics-3.3.1-3.7.src.rpm i386: aeec5e4c97d1ccabf1e52036bb37ca79 kdegraphics-3.3.1-3.7.i386.rpm f48caa317d180ee1b40667c62df4acb6 kdegraphics-devel-3.3.1-3.7.i386.rpm x86_64: 37cf516a06d3f42159ce54c62b901794 kdegraphics-3.3.1-3.7.x86_64.rpm 9b65bf232f163136cf5db28fd82fc661 kdegraphics-devel-3.3.1-3.7.x86_64.rpm Red Hat Enterprise Linux ES version 4: SRPMS: 90ac8bd5592b058f6eb37df331008226 kdegraphics-3.3.1-3.7.src.rpm i386: aeec5e4c97d1ccabf1e52036bb37ca79 kdegraphics-3.3.1-3.7.i386.rpm f48caa317d180ee1b40667c62df4acb6 kdegraphics-devel-3.3.1-3.7.i386.rpm ia64: 3d3b3279d047bfff9cd14271072bd443 kdegraphics-3.3.1-3.7.ia64.rpm 432dea1108d258f6af3964180ab4d179 kdegraphics-devel-3.3.1-3.7.ia64.rpm x86_64: 37cf516a06d3f42159ce54c62b901794 kdegraphics-3.3.1-3.7.x86_64.rpm 9b65bf232f163136cf5db28fd82fc661 kdegraphics-devel-3.3.1-3.7.x86_64.rpm Red Hat Enterprise Linux WS version 4: SRPMS: 90ac8bd5592b058f6eb37df331008226 kdegraphics-3.3.1-3.7.src.rpm i386: aeec5e4c97d1ccabf1e52036bb37ca79 kdegraphics-3.3.1-3.7.i386.rpm f48caa317d180ee1b40667c62df4acb6 kdegraphics-devel-3.3.1-3.7.i386.rpm ia64: 3d3b3279d047bfff9cd14271072bd443 kdegraphics-3.3.1-3.7.ia64.rpm 432dea1108d258f6af3964180ab4d179 kdegraphics-devel-3.3.1-3.7.ia64.rpm x86_64: 37cf516a06d3f42159ce54c62b901794 kdegraphics-3.3.1-3.7.x86_64.rpm 9b65bf232f163136cf5db28fd82fc661 kdegraphics-devel-3.3.1-3.7.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key#package 7. References: https://www.cve.org/CVERecord?id=CVE-2006-0301 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2006 Red Hat, Inc. . The latest update from Red Hat for kdegraphics tackles a significant buffer overflow vulnerability affecting kpdf, reinforcing security measures.. kdegraphics security update, buffer overflow fix, Red Hat advisory. . Severity: Important. LinuxSecurity.com Team
Updated kdegraphics packages that resolve several security issues in kpdf are now available. This update has been rated as having important security impact by the Red Hat Security Response Team.. - --------------------------------------------------------------------- Red Hat Security Advisory Synopsis: Important: kdegraphics security update Advisory ID: RHSA-2005:868-01 Advisory URL: https://access.redhat.com/errata/RHSA-2005:868.html Issue date: 2005-12-20 Updated on: 2005-12-20 Product: Red Hat Enterprise Linux CVE Names: CVE-2005-3191 CVE-2005-3192 CVE-2005-3193 - ---------------------------------------------------------------------1. Summary: Updated kdegraphics packages that resolve several security issues in kpdf are now available. This update has been rated as having important security impact by the Red Hat Security Response Team. 2. Relevant releases/architectures: Red Hat Enterprise Linux AS version 4 - i386, ia64, ppc, s390, s390x, x86_64 Red Hat Enterprise Linux Desktop version 4 - i386, x86_64 Red Hat Enterprise Linux ES version 4 - i386, ia64, x86_64 Red Hat Enterprise Linux WS version 4 - i386, ia64, x86_64 3. Problem description: The kdegraphics packages contain applications for the K Desktop Environment including kpdf, a pdf file viewer. Several flaws were discovered in kpdf. An attacker could construct a carefully crafted PDF file that could cause kpdf to crash or possibly execute arbitrary code when opened. The Common Vulnerabilities and Exposures project assigned the names CVE-2005-3191, CVE-2005-3192, and CVE-2005-3193 to these issues. Users of kpdf should upgrade to these updated packages, which contain a backported patch to resolve these issues. 4. Solution: Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via Red Hat Network. To use Red Hat Network, launch the Red HatUpdate Agent with the following command: up2date This will start an interactive process that will result in the appropriate RPMs being upgraded on your system. 5. Bug IDs fixed (http://bugzilla.redhat.com/): 175105 - CVE-2005-3193 xpdf issues (CVE-2005-3191 CVE-2005-3192) 6. RPMs required: Red Hat Enterprise Linux AS version 4: SRPMS: d72af47a55eabd5bfd0f95538951007d kdegraphics-3.3.1-3.6.src.rpm i386: 216eabcf4313d5a3a66f849cc446cdaf kdegraphics-3.3.1-3.6.i386.rpm 6558e85cef158b8c45e7069cc2a567b4 kdegraphics-devel-3.3.1-3.6.i386.rpm ia64: 7859a256f616e79311a5faf64227bfdf kdegraphics-3.3.1-3.6.ia64.rpm 7f4312d4a79011edd8694f3b19106e78 kdegraphics-devel-3.3.1-3.6.ia64.rpm ppc: 0beeafa85a6715a4040b7355bd21fda5 kdegraphics-3.3.1-3.6.ppc.rpm 4b4880c8edd72320b0fe475cb245a8e2 kdegraphics-devel-3.3.1-3.6.ppc.rpm s390: 64bfbe394e5988987ab7d1784361e39a kdegraphics-3.3.1-3.6.s390.rpm 557cc641cf9c85e0dc44335b747e8970 kdegraphics-devel-3.3.1-3.6.s390.rpm s390x: cf7f965ab80723da2775442c931590d8 kdegraphics-3.3.1-3.6.s390x.rpm b475339a5a98ddda8abf6f1b3838b5c0 kdegraphics-devel-3.3.1-3.6.s390x.rpm x86_64: b68f28b7ceb0a76d5a34cc02c4f6aeaf kdegraphics-3.3.1-3.6.x86_64.rpm 358bd292294d3e5bf6c71da1f7349a0d kdegraphics-devel-3.3.1-3.6.x86_64.rpm Red Hat Enterprise Linux Desktop version 4: SRPMS: d72af47a55eabd5bfd0f95538951007d kdegraphics-3.3.1-3.6.src.rpm i386: 216eabcf4313d5a3a66f849cc446cdaf kdegraphics-3.3.1-3.6.i386.rpm 6558e85cef158b8c45e7069cc2a567b4 kdegraphics-devel-3.3.1-3.6.i386.rpm x86_64: b68f28b7ceb0a76d5a34cc02c4f6aeaf kdegraphics-3.3.1-3.6.x86_64.rpm 358bd292294d3e5bf6c71da1f7349a0d kdegraphics-devel-3.3.1-3.6.x86_64.rpm Red Hat Enterprise Linux ES version 4: SRPMS: d72af47a55eabd5bfd0f95538951007d kdegraphics-3.3.1-3.6.src.rpm i386: 216eabcf4313d5a3a66f849cc446cdaf kdegraphics-3.3.1-3.6.i386.rpm 6558e85cef158b8c45e7069cc2a567b4 kdegraphics-devel-3.3.1-3.6.i386.rpm ia64: 7859a256f616e79311a5faf64227bfdf kdegraphics-3.3.1-3.6.ia64.rpm 7f4312d4a79011edd8694f3b19106e78 kdegraphics-devel-3.3.1-3.6.ia64.rpm x86_64: b68f28b7ceb0a76d5a34cc02c4f6aeaf kdegraphics-3.3.1-3.6.x86_64.rpm 358bd292294d3e5bf6c71da1f7349a0d kdegraphics-devel-3.3.1-3.6.x86_64.rpm Red Hat Enterprise Linux WS version 4: SRPMS: d72af47a55eabd5bfd0f95538951007d kdegraphics-3.3.1-3.6.src.rpm i386: 216eabcf4313d5a3a66f849cc446cdaf kdegraphics-3.3.1-3.6.i386.rpm 6558e85cef158b8c45e7069cc2a567b4 kdegraphics-devel-3.3.1-3.6.i386.rpm ia64: 7859a256f616e79311a5faf64227bfdf kdegraphics-3.3.1-3.6.ia64.rpm 7f4312d4a79011edd8694f3b19106e78 kdegraphics-devel-3.3.1-3.6.ia64.rpm x86_64: b68f28b7ceb0a76d5a34cc02c4f6aeaf kdegraphics-3.3.1-3.6.x86_64.rpm 358bd292294d3e5bf6c71da1f7349a0d kdegraphics-devel-3.3.1-3.6.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key#package 7. References: https://www.cve.org/CVERecord?id=CVE-2005-3191 https://www.cve.org/CVERecord?id=CVE-2005-3192 https://www.cve.org/CVERecord?id=CVE-2005-3193 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2005 Red Hat, Inc. . Essential kdegraphics patch from Red Hat tackles various security threats, bolstering user protection effectively.. Kdegraphics Update, Red Hat Advisory, Software Security Patch. . Severity: Important. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.