[Forgot Password]
Login  Register Subscribe

23631

 
 

115038

 
 

96078

 
 

909

 
 

78009

 
 

109

Paid content will be excluded from the download.


Download | Alert*
OVAL

RHSA-2009:0431-01 -- Redhat kdegraphics

ID: oval:org.secpod.oval:def:500514Date: (C)2012-01-31   (M)2017-10-04
Class: PATCHFamily: unix




The kdegraphics packages contain applications for the K Desktop Environment, including KPDF, a viewer for Portable Document Format files. Multiple integer overflow flaws were found in KPDF"s JBIG2 decoder. An attacker could create a malicious PDF file that would cause KPDF to crash or, potentially, execute arbitrary code when opened. Multiple buffer overflow flaws were found in KPDF"s JBIG2 decoder. An attacker could create a malicious PDF file that would cause KPDF to crash or, potentially, execute arbitrary code when opened. Multiple flaws were found in KPDF"s JBIG2 decoder that could lead to the freeing of arbitrary memory. An attacker could create a malicious PDF file that would cause KPDF to crash or, potentially, execute arbitrary code when opened. Multiple input validation flaws were found in KPDF"s JBIG2 decoder. An attacker could create a malicious PDF file that would cause KPDF to crash or, potentially, execute arbitrary code when opened. Multiple denial of service flaws were found in KPDF"s JBIG2 decoder. An attacker could create a malicious PDF that would cause KPDF to crash when opened. Red Hat would like to thank Braden Thomas and Drew Yao of the Apple Product Security team, and Will Dormann of the CERT/CC for responsibly reporting these flaws. Users are advised to upgrade to these updated packages, which contain backported patches to resolve these issues.

Platform:
Red Hat Enterprise Linux 5
Red Hat Enterprise Linux 4
Product:
kdegraphics
Reference:
RHSA-2009:0431-01
CVE-2009-0146
CVE-2009-0147
CVE-2009-0166
CVE-2009-0799
CVE-2009-0800
CVE-2009-1179
CVE-2009-1180
CVE-2009-1181
CVE-2009-1182
CVE-2009-1183
CVE-2009-0195
CVE    11
CVE-2009-0147
CVE-2009-0146
CVE-2009-0166
CVE-2009-0195
...
CPE    3
cpe:/o:redhat:enterprise_linux:4
cpe:/o:redhat:enterprise_linux:5
cpe:/a:kde:kdegraphics

© 2013 SecPod Technologies