Updated Xpdf packages are now available that fix a vulnerability in which a
maliciously-crafted pdf document could run arbitrary code.
Xpdf is a viewer for Portable Document Format (PDF) files.
During an audit of CUPS, a printing system, Zen Parsec found an integer
overflow vulnerability in the pdftops filter. Since the code for pdftops
is taken from the Xpdf project, all versions of Xpdf including 2.01 are
also vulnerable to this issue. An attacker could create a PDF
file that could execute arbitrary code. This could would have the same
access privileges as the user who viewed the file with Xpdf.
All users of Xpdf are advised to upgrade to these erratum packages. For
Red Hat Linux 8.0 we have included new packages based on Xpdf 1.01 with a
patch to correct this issue. For Red Hat Linux 7.0, 7.1, 7.2, and 7.3 we
have upgraded Xpdf to version 1.00 with a patch to correct this issue. For
Red Hat Linux 6.2 we have upgraded Xpdf to version 0.92 with a patch to
correct this issue.
| Red Hat Linux 6.2 |
|
| SRPMS: |
ftp://updates.redhat.com/6.2/en/os/SRPMS/xpdf-0.92-1.62.0.src.rpm
Missing file |
14f5a760b10a2022fe11b13a608679e4 |
| |
| IA-32: |
ftp://updates.redhat.com/6.2/en/os/i386/xpdf-0.92-1.62.0.i386.rpm
Missing file |
84273042eac769bca8e0ae41e40cbb51 |
| |
| Red Hat Linux 7.0 |
|
| SRPMS: |
ftp://updates.redhat.com/7.0/en/os/SRPMS/xpdf-0.92-2.70.0.src.rpm
Missing file |
2ec914d67d16b66eb4777793c4927d2b |
| |
| IA-32: |
ftp://updates.redhat.com/7.0/en/os/i386/xpdf-0.92-2.70.0.i386.rpm
Missing file |
e9f8f9b571951d832dcfe6310c222600 |
| |
| Red Hat Linux 7.1 |
|
| SRPMS: |
xpdf-0.92-4.71.0.src.rpm
File outdated by: RHSA-2003:196 |
777407e0f43e7586f4ef22681eb5311b |
| |
| IA-32: |
xpdf-0.92-4.71.0.i386.rpm
File outdated by: RHSA-2003:196 |
69f703be285030506d5775c7e258353e |
| |
| Red Hat Linux 7.2 |
|
| SRPMS: |
xpdf-0.92-8.src.rpm
File outdated by: RHSA-2003:196 |
6aef839487e9ef365c8a1e083cdb8d40 |
| |
| IA-32: |
xpdf-0.92-8.i386.rpm
File outdated by: RHSA-2003:196 |
a5b8632b5e3fdae729fd138c79511f37 |
| |
| IA-64: |
xpdf-0.92-8.ia64.rpm
File outdated by: RHSA-2003:196 |
9833d7aaa358bf91daac2927d85ecca4 |
| |
| Red Hat Linux 7.3 |
|
| SRPMS: |
xpdf-1.00-5.src.rpm
File outdated by: RHSA-2003:196 |
d3f8e5d7bbfe3c10c924b8e8e2c855e2 |
| |
| IA-32: |
xpdf-1.00-5.i386.rpm
File outdated by: RHSA-2003:196 |
970dcce631dd221352e4079de6fc8cc8 |
xpdf-chinese-simplified-1.00-5.i386.rpm
File outdated by: RHSA-2003:196 |
1281db16a674bbba70a40f22b8da44c1 |
xpdf-chinese-traditional-1.00-5.i386.rpm
File outdated by: RHSA-2003:196 |
f9ad4618251a7aaabc62767dda269177 |
xpdf-japanese-1.00-5.i386.rpm
File outdated by: RHSA-2003:196 |
c796d0feb9f67344104393c82c4c707c |
xpdf-korean-1.00-5.i386.rpm
File outdated by: RHSA-2003:196 |
8313eca768d1741372b18a304400bec9 |
| |
| Red Hat Linux 8.0 |
|
| SRPMS: |
xpdf-1.01-10.src.rpm
File outdated by: RHSA-2003:196 |
d9e8a55e8fc1a1c2accf738372f541f1 |
| |
| IA-32: |
xpdf-1.01-10.i386.rpm
File outdated by: RHSA-2003:196 |
5ff0fab12ef736f60e9d9608a4c17d59 |
xpdf-chinese-simplified-1.01-10.i386.rpm
File outdated by: RHSA-2003:196 |
b175f4484b7b652164b4065b9c04f700 |
xpdf-chinese-traditional-1.01-10.i386.rpm
File outdated by: RHSA-2003:196 |
b79bb5155ef492835453dd0eb07af345 |
xpdf-japanese-1.01-10.i386.rpm
File outdated by: RHSA-2003:196 |
15058d3a0a53536f6300d4e5c52c00b1 |
xpdf-korean-1.01-10.i386.rpm
File outdated by: RHSA-2003:196 |
028755012a882c6ed4024b7b4c601911 |
| |