First published: Thu Oct 15 2009(Updated: )
The kdegraphics packages contain applications for the K Desktop<br>Environment, including KPDF, a viewer for Portable Document Format (PDF)<br>files.<br>Multiple integer overflow flaws were found in KPDF. An attacker could<br>create a malicious PDF file that would cause KPDF to crash or, potentially,<br>execute arbitrary code when opened. (CVE-2009-0791, CVE-2009-1188,<br>CVE-2009-3604, CVE-2009-3608, CVE-2009-3609)<br>Red Hat would like to thank Adam Zabrocki for reporting the CVE-2009-3604<br>issue, and Chris Rohlf for reporting the CVE-2009-3608 issue.<br>Users are advised to upgrade to these updated packages, which contain a<br>backported patch to resolve these issues.
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/kdegraphics | <3.3.1-15.el4_8.2 | 3.3.1-15.el4_8.2 |
redhat/kdegraphics | <3.3.1-15.el4_8.2 | 3.3.1-15.el4_8.2 |
redhat/kdegraphics-devel | <3.3.1-15.el4_8.2 | 3.3.1-15.el4_8.2 |
redhat/kdegraphics-devel | <3.3.1-15.el4_8.2 | 3.3.1-15.el4_8.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.