[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248268

 
 

909

 
 

195051

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

RHSA-2009:0430-01 -- Redhat xpdf

ID: oval:org.secpod.oval:def:500668Date: (C)2012-01-31   (M)2024-01-02
Class: PATCHFamily: unix




Xpdf is an X Window System based viewer for Portable Document Format files. Multiple integer overflow flaws were found in Xpdf"s JBIG2 decoder. An attacker could create a malicious PDF file that would cause Xpdf to crash or, potentially, execute arbitrary code when opened. Multiple buffer overflow flaws were found in Xpdf"s JBIG2 decoder. An attacker could create a malicious PDF file that would cause Xpdf to crash or, potentially, execute arbitrary code when opened. Multiple flaws were found in Xpdf"s JBIG2 decoder that could lead to the freeing of arbitrary memory. An attacker could create a malicious PDF file that would cause Xpdf to crash or, potentially, execute arbitrary code when opened. Multiple input validation flaws were found in Xpdf"s JBIG2 decoder. An attacker could create a malicious PDF file that would cause Xpdf to crash or, potentially, execute arbitrary code when opened. Multiple denial of service flaws were found in Xpdf"s JBIG2 decoder. An attacker could create a malicious PDF that would cause Xpdf to crash when opened. Red Hat would like to thank Braden Thomas and Drew Yao of the Apple Product Security team, and Will Dormann of the CERT/CC for responsibly reporting these flaws. Users are advised to upgrade to this updated package, which contains backported patches to correct these issues.

Platform:
Red Hat Enterprise Linux 4
Red Hat Enterprise Linux 3
Product:
xpdf
Reference:
RHSA-2009:0430-01
CVE-2009-0146
CVE-2009-0147
CVE-2009-0166
CVE-2009-0799
CVE-2009-0800
CVE-2009-1179
CVE-2009-1180
CVE-2009-1181
CVE-2009-1182
CVE-2009-1183
CVE    10
CVE-2009-0800
CVE-2009-0799
CVE-2009-0147
CVE-2009-0146
...
CPE    2
cpe:/o:redhat:enterprise_linux:4
cpe:/o:redhat:enterprise_linux:3

© SecPod Technologies