[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

rPSA-2007-0013-1 poppler tetex tetex-afm tetex-dvips tetex-fonts tetex-latex tetex-xdvi


rPath Security Advisory: 2007-0013-1
Published: 2007-01-23
Products: rPath Linux 1
Rating: Major
Exposure Level Classification:
    Indirect User Deterministic Denial of Service
Updated Versions:
    poppler=/suppressed:devel//1/0.4.5-1.1-1
    tetex=/suppressed:devel//1/2.0.2-28.4-1
    tetex-afm=/suppressed:devel//1/2.0.2-28.4-1
    tetex-dvips=/suppressed:devel//1/2.0.2-28.4-1
    tetex-fonts=/suppressed:devel//1/2.0.2-28.4-1
    tetex-latex=/suppressed:devel//1/2.0.2-28.4-1
    tetex-xdvi=/suppressed:devel//1/2.0.2-28.4-1

References:
    http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0104
    https://issues.rpath.com/browse/RPL-964

Description:
    Previous versions of the poppler and tetex packages are vulnerable to
    an attack in which an intentionally malformed PDF file can create at
    least a minor Denial of Service attack on the PDF application, and
    may possibly allow for directed or arbitrary code execution.


Mail converted by mhonarc 2.6.15
This archive provided courtesy of JSW4.NET, Internet Hosting Services for Small Business.