First published: Wed Apr 15 2009(Updated: )
An integer overflow flaw was found in xpdf's JBIG2 decoder. This flaw could result in arbitrary code execute with the permissions of the user running xpdf. Will Dormann of the CERT/CC created the extensive testsuite for the JBIG2 decoder in various PDF libraries that found this flaw. Acknowledgements: Red Hat would like to thank Will Dormann of the CERT/CC for responsibly reporting this flaw.
Affected Software | Affected Version | How to fix |
---|---|---|
Xpdf |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of REDHAT-BUG-495889 is critical due to the potential for arbitrary code execution.
To fix REDHAT-BUG-495889, you should update to the latest version of xpdf provided by your distribution.
The potential impacts of REDHAT-BUG-495889 include unauthorized access and control over the system running xpdf.
The REDHAT-BUG-495889 vulnerability was discovered by Will Dormann of CERT/CC.
Yes, REDHAT-BUG-495889 specifically affects the JBIG2 decoder in the xpdf software.