First published: Wed Apr 15 2009(Updated: )
Multiple NULL derefernce flaws were found in xpdf's JBIG2 decoder. A carefully crafted PDF file could cause xpdf to crash when opened. Will Dormann of the CERT/CC created the extensive testsuite for the JBIG2 decoder in various PDF libraries that found this flaw. Acknowledgements: Red Hat would like to thank Will Dormann of the CERT/CC for responsibly reporting these flaws.
Affected Software | Affected Version | How to fix |
---|---|---|
Xpdf |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of REDHAT-BUG-495894 is considered high due to the potential for crashes caused by manipulated PDF files.
To fix REDHAT-BUG-495894, update Xpdf to the latest version available from Red Hat or your software distributor.
The affected software for REDHAT-BUG-495894 is Xpdf, specifically in its JBIG2 decoder.
No, REDHAT-BUG-495894 does not lead to remote code execution, but it can crash the application when opened.
Currently, the recommended approach for REDHAT-BUG-495894 is to upgrade the software, as no specific workaround has been provided.