Jump to content

Advisories MDVSA-2010:086: kdegraphics


paul
 Share

Recommended Posts

Multiple vulnerabilities has been found and corrected in kpdf

(kdegraphics):

 

Integer overflow in the ObjectStream::ObjectStream function in XRef.cc

in Xpdf 3.x before 3.02pl4 and Poppler before 0.12.1, as used in

GPdf, kdegraphics KPDF, CUPS pdftops, and teTeX, might allow remote

attackers to execute arbitrary code via a crafted PDF document that

triggers a heap-based buffer overflow (CVE-2009-3608).

 

Integer overflow in the ImageStream::ImageStream function in Stream.cc

in Xpdf before 3.02pl4 and Poppler before 0.12.1, as used in GPdf,

kdegraphics KPDF, and CUPS pdftops, allows remote attackers to

cause a denial of service (application crash) via a crafted PDF

document that triggers a NULL pointer dereference or buffer over-read

(CVE-2009-3609).

 

The updated packages have been patched to correct thess issues.

Link to comment
Share on other sites

Guest
This topic is now closed to further replies.
 Share

×
×
  • Create New...