Donations

Donate to support our development efforts.


Languages
Change language | Change language | Change language | Change language | Change language | Change language | Change language | Change language | Change language | Change language
Share

Share Frugalware with your friends.








Frugalware
on Google+
Recent updates
devel-extra/
 python-markdown
2.3.1-1-x86_64
xapps-extra/
 chromium-browser
27.0.1453.93-1-x86_64
misc-fonts/
 fontconfig
2.10.93-1-arm
devel-core/python
2.7.5-1-arm
devel-extra/
 python-tools
2.7.5-1-arm
devel-extra/
 python-sqlite3
2.7.5-1-arm
gnome-extra/
 gnome-nettool
3.8.0-1-i686
gnome-extra/gnote
3.8.1-2-i686
gnome-extra/gnote
3.8.1-2-x86_64
gnome-extra/
 gnome-nettool
3.8.0-1-x86_64

RSS
Information
Go Frugalware, Go
Valid XHTML 1.0!
Valid CSS!
Valid RSS!
Server information
Uptime:
36 day(s) 0 h 33 m 57 s
Package:xpdf
Date:2011-08-22
Posted by:Miklos Vajna
Vulnerable version:3.02-6
Unaffected version:3.02-7mores1
Bug tracker entry:http://bugs.frugalware.org/task/4236
CVEs:http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1188 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3603 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3604 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3606 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3608 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3609
Description:Some vulnerabilities have been reported in Xpdf, which can be exploited by malicious people to potentially compromise a user's system. 1) Multiple integer overflows in "SplashBitmap::SplashBitmap()" can be exploited to cause heap-based buffer overflows. 2) An integer overflow error in "ObjectStream::ObjectStream()" can be exploited to cause a heap-based buffer overflow. 3) Multiple integer overflows in "Splash::drawImage()" can be exploited to cause heap-based buffer overflows. 4) An integer overflow error in "PSOutputDev::doImageL1Sep()" can be exploited to cause a heap-based buffer overflow when converting a PDF document to a PS file. Successful exploitation of the vulnerabilities may allow execution of arbitrary code by tricking a user into opening a specially crafted PDF file.
© 2003-2011. The Frugalware Developer Team