| Description: | The remote host is missing an update to poppler announced via advisory USN-631-1.
A security issue affects the following Ubuntu releases:
Ubuntu 7.10 Ubuntu 8.04 LTS
This advisory also applies to the corresponding versions of Kubuntu, Edubuntu, and Xubuntu.
Details follow:
Felipe Andres Manzano discovered that poppler did not correctly initialize certain page widgets. If a user were tricked into viewing a malicious PDF file, a remote attacker could exploit this to crash applications linked against poppler, leading to a denial of service.
Solution: The problem can be corrected by upgrading your system to the following package versions:
Ubuntu 7.10: libpoppler2 0.6-0ubuntu2.3
Ubuntu 8.04 LTS: libpoppler2 0.6.4-1ubuntu3.1
In general, a standard system upgrade is sufficient to effect the necessary changes.
http://www.securityspace.com/smysecure/catid.html?in=USN-631-1
Risk factor : High |