Bug 19664 - JBIG2 Processing Multiple Security Vulnerabilities
: JBIG2 Processing Multiple Security Vulnerabilities
Status: CLOSED FIXED
: Sisyphus
(All bugs in Sisyphus/poppler)
: unstable
: all Linux
: P3 blocker
Assigned To:
:
: http://www.securityfocus.com/bid/34568
: security
:
:
  Show dependency tree
 
Reported: 2009-04-18 14:36 by
Modified: 2009-04-29 14:14 (History)


Attachments


Note

You need to log in before you can comment on or make changes to this bug.


Description From 2009-04-18 14:36:14
CVE-2009-0799 xpdf OOB Read
CVE-2009-0800 xpdf Multiple Input Validation Flaws
CVE-2009-1179 xpdf Integer Overflow
CVE-2009-1180 xpdf Invalid free()
CVE-2009-1181 xpdf NULL dereference DoS
CVE-2009-1182 xpdf MMR Decoder Buffer Overflows
CVE-2009-1183 xpdf MMR Infinite Loop DoS

Апстримом выпущена новая версия 0.10.6 poppler, исправляющая эти проблемы
------- Comment #1 From 2009-04-18 14:37:27 -------
security -> blo
------- Comment #2 From 2009-04-20 17:05:39 -------
Сделал у себя ветку security_fixes, где развернул 0.10.6:
http://git.altlinux.org/people/crux/packages/?p=poppler.git;a=commit;h=5b029c84e30f2028faa4e376e61c79875ae37833
------- Comment #3 From 2009-04-21 12:05:59 -------
poppler-0.10.6-alt2
------- Comment #4 From 2009-04-22 16:42:42 -------
ack