First published: Thu Oct 15 2009(Updated: )
Poppler is a Portable Document Format (PDF) rendering library, used by<br>applications such as Evince.<br>Multiple integer overflow flaws were found in poppler. An attacker could<br>create a malicious PDF file that would cause applications that use poppler<br>(such as Evince) to crash or, potentially, execute arbitrary code when<br>opened. (CVE-2009-3603, CVE-2009-3608, CVE-2009-3609)<br>Red Hat would like to thank Chris Rohlf for reporting the CVE-2009-3608<br>issue.<br>This update also corrects a regression introduced in the previous poppler<br>security update, RHSA-2009:0480, that prevented poppler from rendering<br>certain PDF documents correctly. (BZ#528147)<br>Users are advised to upgrade to these updated packages, which contain<br>backported patches to resolve these issues.
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/poppler | <0.5.4-4.4.el5_4.11 | 0.5.4-4.4.el5_4.11 |
redhat/poppler | <0.5.4-4.4.el5_4.11 | 0.5.4-4.4.el5_4.11 |
redhat/poppler-devel | <0.5.4-4.4.el5_4.11 | 0.5.4-4.4.el5_4.11 |
redhat/poppler-devel | <0.5.4-4.4.el5_4.11 | 0.5.4-4.4.el5_4.11 |
redhat/poppler-utils | <0.5.4-4.4.el5_4.11 | 0.5.4-4.4.el5_4.11 |
redhat/poppler-utils | <0.5.4-4.4.el5_4.11 | 0.5.4-4.4.el5_4.11 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.