First published: Thu Oct 15 2009(Updated: )
The kdegraphics packages contain applications for the K Desktop<br>Environment, including KPDF, a viewer for Portable Document Format (PDF)<br>files.<br>Multiple integer overflow flaws were found in KPDF. An attacker could<br>create a malicious PDF file that would cause KPDF to crash or, potentially,<br>execute arbitrary code when opened. (CVE-2009-0791, CVE-2009-1188,<br>CVE-2009-3604, CVE-2009-3606, CVE-2009-3608, CVE-2009-3609)<br>Red Hat would like to thank Adam Zabrocki for reporting the CVE-2009-3604<br>issue, and Chris Rohlf for reporting the CVE-2009-3608 issue.<br>Users are advised to upgrade to these updated packages, which contain a<br>backported patch to resolve these issues.
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/kdegraphics | <3.5.4-15.el5_4.2 | 3.5.4-15.el5_4.2 |
redhat/kdegraphics | <3.5.4-15.el5_4.2 | 3.5.4-15.el5_4.2 |
redhat/kdegraphics-devel | <3.5.4-15.el5_4.2 | 3.5.4-15.el5_4.2 |
redhat/kdegraphics-devel | <3.5.4-15.el5_4.2 | 3.5.4-15.el5_4.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
RHSA-2009:1502 contains multiple integer overflow flaws in KPDF.
An attacker could create a malicious PDF file that could cause KPDF to crash.
To remediate RHSA-2009:1502, update the kdegraphics and kdegraphics-devel packages to version 3.5.4-15.el5_4.2.
The kdegraphics and kdegraphics-devel packages are affected by vulnerability RHSA-2009:1502.
You should update to version 3.5.4-15.el5_4.2 to fix vulnerability RHSA-2009:1502.