CESA-2009:1680 -- centos 4 i386 xpdfID: oval:org.secpod.oval:def:200392 | Date: (C)2012-01-31 (M)2022-03-15 |
Class: PATCH | Family: unix |
Xpdf is an X Window System based viewer for Portable Document Format files. Petr Gajdos and Christian Kornacker of SUSE reported a buffer overflow flaw in Xpdf"s Type 1 font parser. A specially-crafted PDF file with an embedded Type 1 font could cause Xpdf to crash or, possibly, execute arbitrary code when opened. Users are advised to upgrade to this updated package, which contains a backported patch to correct this issue.