First published: Thu Oct 01 2009(Updated: )
Integer overflow in the ObjectStream::ObjectStream function in XRef.cc in Xpdf 3.x before 3.02pl4 and Poppler before 0.12.1, as used in GPdf, kdegraphics KPDF, CUPS pdftops, and teTeX, might allow remote attackers to execute arbitrary code via a crafted PDF document that triggers a heap-based buffer overflow.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/xpdf | <1:3.00-22.el4_8.1 | 1:3.00-22.el4_8.1 |
redhat/gpdf | <0:2.8.2-7.7.2.el4_8.5 | 0:2.8.2-7.7.2.el4_8.5 |
redhat/kdegraphics | <7:3.3.1-15.el4_8.2 | 7:3.3.1-15.el4_8.2 |
redhat/kdegraphics | <7:3.5.4-15.el5_4.2 | 7:3.5.4-15.el5_4.2 |
redhat/poppler | <0:0.5.4-4.4.el5_4.11 | 0:0.5.4-4.4.el5_4.11 |
redhat/cups | <1:1.3.7-11.el5_4.3 | 1:1.3.7-11.el5_4.3 |
redhat/tetex | <0:3.0-33.8.el5_5.5 | 0:3.0-33.8.el5_5.5 |
Foolabs Xpdf | =3.02pl1 | |
Foolabs Xpdf | =3.02pl2 | |
Foolabs Xpdf | =3.02pl3 | |
Glyphandcog Xpdfreader | =3.00 | |
Glyphandcog Xpdfreader | =3.01 | |
Glyphandcog Xpdfreader | =3.02 | |
Poppler Poppler | <=0.12.0 | |
Poppler Poppler | =0.1 | |
Poppler Poppler | =0.1.1 | |
Poppler Poppler | =0.1.2 | |
Poppler Poppler | =0.2.0 | |
Poppler Poppler | =0.3.0 | |
Poppler Poppler | =0.3.1 | |
Poppler Poppler | =0.3.2 | |
Poppler Poppler | =0.3.3 | |
Poppler Poppler | =0.4.0 | |
Poppler Poppler | =0.4.1 | |
Poppler Poppler | =0.4.2 | |
Poppler Poppler | =0.4.3 | |
Poppler Poppler | =0.4.4 | |
Poppler Poppler | =0.5.0 | |
Poppler Poppler | =0.5.1 | |
Poppler Poppler | =0.5.2 | |
Poppler Poppler | =0.5.3 | |
Poppler Poppler | =0.5.4 | |
Poppler Poppler | =0.5.9 | |
Poppler Poppler | =0.6.0 | |
Poppler Poppler | =0.6.1 | |
Poppler Poppler | =0.6.2 | |
Poppler Poppler | =0.6.3 | |
Poppler Poppler | =0.6.4 | |
Poppler Poppler | =0.7.0 | |
Poppler Poppler | =0.7.1 | |
Poppler Poppler | =0.7.2 | |
Poppler Poppler | =0.7.3 | |
Poppler Poppler | =0.8.0 | |
Poppler Poppler | =0.8.1 | |
Poppler Poppler | =0.8.2 | |
Poppler Poppler | =0.8.3 | |
Poppler Poppler | =0.8.4 | |
Poppler Poppler | =0.8.6 | |
Poppler Poppler | =0.8.7 | |
Poppler Poppler | =0.9.0 | |
Poppler Poppler | =0.9.1 | |
Poppler Poppler | =0.9.2 | |
Poppler Poppler | =0.9.3 | |
Poppler Poppler | =0.10.0 | |
Poppler Poppler | =0.10.1 | |
Poppler Poppler | =0.10.2 | |
Poppler Poppler | =0.10.3 | |
Poppler Poppler | =0.10.4 | |
Poppler Poppler | =0.10.5 | |
Poppler Poppler | =0.10.6 | |
Poppler Poppler | =0.10.7 | |
Poppler Poppler | =0.11.0 | |
Poppler Poppler | =0.11.1 | |
Poppler Poppler | =0.11.2 | |
Poppler Poppler | =0.11.3 | |
Glyph And Cog Pdftops | ||
Gnome Gpdf | ||
Kde Kpdf | ||
Tetex Tetex |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)