REDHAT-BUG-495896: Buffer Overflow
Multiple buffer overflow flaws were found in xpdf's JBIG2 MMR decoder. A carefully crafted PDF file could result in arbitrary code execute with the permissions of the user running xpdf.
Will Dormann of the CERT/CC created the extensive testsuite for the JBIG2 decoder in various PDF libraries that found this flaw.
Acknowledgements:
Red Hat would like to thank Will Dormann of the CERT/CC for responsibly reporting these flaws.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-495896?
The severity of REDHAT-BUG-495896 is critical due to the potential for arbitrary code execution.
How do I fix REDHAT-BUG-495896?
To fix REDHAT-BUG-495896, update to the latest version of xpdf as recommended in the security advisories.
What software is affected by REDHAT-BUG-495896?
The affected software for REDHAT-BUG-495896 is xpdf.
Can REDHAT-BUG-495896 be exploited remotely?
Yes, REDHAT-BUG-495896 can be exploited remotely through maliciously crafted PDF files.
Who reported the REDHAT-BUG-495896 vulnerability?
Will Dormann of the CERT/CC reported the REDHAT-BUG-495896 vulnerability after extensive testing.