--------------------------------------------------------------------- Fedora Legacy Test Update Notification FEDORALEGACY-2005-2352 Bugzilla https://bugzilla.fedora.us/show_bug.cgi?id=2352 2005-02-04 ---------------------------------------------------------------------
Name : xpdf Versions : rh7.3: xpdf-1.00-7.4.legacy Versions : rh9: xpdf-2.01-11.3.legacy Versions : fc1: xpdf-2.03-1.3.legacy Summary : A PDF file viewer for the X Window System. Description : Xpdf is an X Window System based viewer for Portable Document Format (PDF) files. Xpdf is a small and efficient program which uses standard X fonts.
--------------------------------------------------------------------- Update Information:
Updated Xpdf packages that fix several security issues are now available.
Xpdf is an X Window System based viewer for Portable Document Format (PDF) files.
During a source code audit, Chris Evans and others discovered a number of integer overflow bugs that affected all versions of xpdf. An attacker could construct a carefully crafted PDF file that could cause xpdf to crash or possibly execute arbitrary code when opened. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CAN-2004-0888 to this issue.
A buffer overflow flaw was found in the Gfx::doImage function of Xpdf. An attacker could construct a carefully crafted PDF file that could cause Xpdf to crash or possibly execute arbitrary code when opened. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CAN-2004-1125 to this issue.
A buffer overflow flaw was found when processing the /Encrypt /Length tag. An attacker could construct a carefully crafted PDF file that could cause Xpdf to crash or possibly execute arbitrary code when opened. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CAN-2005-0064 to this issue.
Users of xpdf are advised to upgrade to these errata packages, which contain backported patches correcting these issues.
--------------------------------------------------------------------- Changelogs
rh73: * Wed Jan 19 2005 Rob Myers <rob myers gtri gatech edu> 1.00-7.4.legacy - patch for CAN-2005-0064 (FL #2352) - use better patch for CAN-2004-1125
* Thu Dec 23 2004 Rob Myers <rob myers gtri gatech edu> 1.00-7.3.legacy - patch for CAN-2004-1125 (FL #2352)
* Thu Oct 28 2004 Rob Myers <rob myers gtri gatech edu> 1.00-7.1.legacy - patch for CAN-2004-0888 CAN-2004-0889 (FL #2186)
rh9: * Wed Jan 19 2005 Rob Myers <rob myers gtri gatech edu> 2.01-11.3.legacy - patch for CAN-2005-0064 (FL #2352) - use better patch for CAN-2004-1125
* Thu Dec 23 2004 Rob Myers <rob myers gtri gatech edu> 2.01-11.2.legacy - patch for CAN-2004-1125 (FL #2352)
* Thu Oct 28 2004 Rob Myers <rob myers gtri gatech edu> 2.01-11.1.legacy - patch for CAN-2004-0888 CAN-2004-0889 (FL #2186) - added simple non-security patch for xfont fix
fc1: * Wed Jan 19 2005 Rob Myers <rob myers gtri gatech edu> 1:2.03-1.3.legacy - patch for CAN-2005-0064 (FL #2352) - use better patch for CAN-2004-1125
* Thu Dec 23 2004 Rob Myers <rob myers gtri gatech edu> 1:2.03-1.2.legacy - patch for CAN-2004-1125 (FL #2352)
* Thu Oct 21 2004 Rob Myers <rob myers gtri gatech edu> 1:2.03-1.1.legacy - patch for CAN-2004-0888 CAN-2004-0889 (FL #2186) - include simple non-security xfont patch - fix files listed twice for /usr/share/xpdf/locales
--------------------------------------------------------------------- This update can be downloaded from: http://download.fedoralegacy.org/ (sha1sums)
Attachment:
signature.asc
Description: OpenPGP digital signature