An updated gpdf package that fixes two security issues is now available.
This update has been rated as having important security impact by the Red Hat
Security Response Team.
GPdf is a viewer for Portable Document Format (PDF) files for GNOME.
A buffer overflow flaw was found in the Gfx::doImage function of Xpdf which
also affects GPdf due to a shared codebase. An attacker could construct a
carefully crafted PDF file that could cause GPdf to crash or possibly
execute arbitrary code when opened. The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2004-1125 to
this issue.
A buffer overflow flaw was found in the Decrypt::makeFileKey2 function of
Xpdf which also affects GPdf due to a shared codebase. An attacker could
construct a carefully crafted PDF file that could cause GPdf to crash or
possibly execute arbitrary code when opened. The Common Vulnerabilities and
Exposures project (cve.mitre.org) has assigned the name CAN-2005-0064 to
this issue.
During a source code audit, Chris Evans and others discovered a number of
integer overflow bugs that affected all versions of Xpdf, which also
affects GPdf due to a shared codebase. An attacker could construct a
carefully crafted PDF file that could cause GPdf to crash or possibly
execute arbitrary code when opened. This issue was assigned the name
CAN-2004-0888 by The Common Vulnerabilities and Exposures project
(cve.mitre.org). Red Hat Enterprise Linux 4 contained a fix for this issue,
but it was found to be incomplete and left 64-bit architectures vulnerable.
The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CAN-2005-0206 to this issue.
Users should update to this erratum package which contains backported
patches to correct these issues.
Before applying this update, make sure that all previously-released
errata relevant to your system have been applied. Use Red Hat
Network to download and update your packages. To launch the Red Hat
Update Agent, use the following command:
up2date
For information on how to install packages manually, refer to the
following Web page for the System Administration or Customization
guide specific to your system:
http://www.redhat.com/docs/manuals/enterprise/
| Red Hat Desktop (v. 4) |
|
| SRPMS: |
| gpdf-2.8.2-4.3.src.rpm |
0d2d40d1e98b5e2ecbebabf18f4941f7 |
| |
| IA-32: |
gpdf-2.8.2-4.3.i386.rpm
File outdated by: RHSA-2008:0262 |
bd095233bada6a9596cc0a27a88c3991 |
| |
| x86_64: |
gpdf-2.8.2-4.3.x86_64.rpm
File outdated by: RHSA-2008:0262 |
7438f03d85d8e28d180fa4aebc16e624 |
| |
| Red Hat Enterprise Linux AS (v. 4) |
|
| SRPMS: |
| gpdf-2.8.2-4.3.src.rpm |
0d2d40d1e98b5e2ecbebabf18f4941f7 |
| |
| IA-32: |
gpdf-2.8.2-4.3.i386.rpm
File outdated by: RHSA-2008:0262 |
bd095233bada6a9596cc0a27a88c3991 |
| |
| IA-64: |
gpdf-2.8.2-4.3.ia64.rpm
File outdated by: RHSA-2008:0262 |
e8ad37d8c0c724526af8d0d59f7bc8e3 |
| |
| PPC: |
gpdf-2.8.2-4.3.ppc.rpm
File outdated by: RHSA-2008:0262 |
226b1a316072a0aa69e9c8729a8a37ed |
| |
| s390: |
gpdf-2.8.2-4.3.s390.rpm
File outdated by: RHSA-2008:0262 |
7945af0b72f4ddc8942d00a8b279fc1c |
| |
| s390x: |
gpdf-2.8.2-4.3.s390x.rpm
File outdated by: RHSA-2008:0262 |
18935e86dc836057e5bc7bb0da86d281 |
| |
| x86_64: |
gpdf-2.8.2-4.3.x86_64.rpm
File outdated by: RHSA-2008:0262 |
7438f03d85d8e28d180fa4aebc16e624 |
| |
| Red Hat Enterprise Linux ES (v. 4) |
|
| SRPMS: |
| gpdf-2.8.2-4.3.src.rpm |
0d2d40d1e98b5e2ecbebabf18f4941f7 |
| |
| IA-32: |
gpdf-2.8.2-4.3.i386.rpm
File outdated by: RHSA-2008:0262 |
bd095233bada6a9596cc0a27a88c3991 |
| |
| IA-64: |
gpdf-2.8.2-4.3.ia64.rpm
File outdated by: RHSA-2008:0262 |
e8ad37d8c0c724526af8d0d59f7bc8e3 |
| |
| x86_64: |
gpdf-2.8.2-4.3.x86_64.rpm
File outdated by: RHSA-2008:0262 |
7438f03d85d8e28d180fa4aebc16e624 |
| |
| Red Hat Enterprise Linux WS (v. 4) |
|
| SRPMS: |
| gpdf-2.8.2-4.3.src.rpm |
0d2d40d1e98b5e2ecbebabf18f4941f7 |
| |
| IA-32: |
gpdf-2.8.2-4.3.i386.rpm
File outdated by: RHSA-2008:0262 |
bd095233bada6a9596cc0a27a88c3991 |
| |
| IA-64: |
gpdf-2.8.2-4.3.ia64.rpm
File outdated by: RHSA-2008:0262 |
e8ad37d8c0c724526af8d0d59f7bc8e3 |
| |
| x86_64: |
gpdf-2.8.2-4.3.x86_64.rpm
File outdated by: RHSA-2008:0262 |
7438f03d85d8e28d180fa4aebc16e624 |
| |
(The unlinked packages above are only available from the Red Hat Network)
|
144210 - CAN-2004-1125 gpdf buffer overflow
145054 - CAN-2005-0064 xpdf buffer overflow
147518 - CAN-2004-0888 xpdf integer overflows