rPath Security Advisory: 2007-0013-1
Published: 2007-01-23
Products: rPath Linux 1
Rating: Major
Exposure Level Classification:
Indirect User Deterministic Denial of Service
Updated Versions:
poppler=/suppressed:devel//1/0.4.5-1.1-1
tetex=/suppressed:devel//1/2.0.2-28.4-1
tetex-afm=/suppressed:devel//1/2.0.2-28.4-1
tetex-dvips=/suppressed:devel//1/2.0.2-28.4-1
tetex-fonts=/suppressed:devel//1/2.0.2-28.4-1
tetex-latex=/suppressed:devel//1/2.0.2-28.4-1
tetex-xdvi=/suppressed:devel//1/2.0.2-28.4-1
References:
http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0104
https://issues.rpath.com/browse/RPL-964
Description:
Previous versions of the poppler and tetex packages are vulnerable to
an attack in which an intentionally malformed PDF file can create at
least a minor Denial of Service attack on the PDF application, and
may possibly allow for directed or arbitrary code execution.
Mail converted by mhonarc 2.6.15
This archive provided courtesy of JSW4.NET, Internet Hosting Services for Small Business.