REDHAT-BUG-495892: High severity xpdf vulnerability
An invalid free() flaw was found in xpdf's JBIG2 decoder. If a malicious PDF file could free() attacker controlled data, it may be possible to execute arbitrary code with the permissions of the user running xpdf.
Will Dormann of the CERT/CC created the extensive testsuite for the JBIG2 decoder in various PDF libraries that found this flaw.
Acknowledgements:
Red Hat would like to thank Will Dormann of the CERT/CC for responsibly reporting this flaw.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-495892?
The severity of REDHAT-BUG-495892 is high due to the potential for arbitrary code execution.
How do I fix REDHAT-BUG-495892?
To fix REDHAT-BUG-495892, update xpdf to the latest version that addresses the JBIG2 decoder flaw.
What are the potential impacts of REDHAT-BUG-495892?
The potential impacts of REDHAT-BUG-495892 include system compromise and unauthorized access to sensitive information.
Which versions of xpdf are affected by REDHAT-BUG-495892?
xpdf versions prior to the latest patched release may be affected by REDHAT-BUG-495892.
Who reported the vulnerability REDHAT-BUG-495892?
Will Dormann of CERT/CC reported the vulnerability REDHAT-BUG-495892.