Description: | Description:
The remote host is missing an update to kdegraphics announced via advisory FEDORA-2004-357.
A problem with PDF handling was discovered by Chris Evans, and has been fixed. The Common Vulnerabilities and Exposures project (www.mitre.org) has assigned the name CVE-2004-0888 to this issue.
A number of buffer overflow bugs that affect libtiff have been found. The kfax application contains a copy of the libtiff code used for parsing TIFF files and is therefore affected by these bugs. An attacker who has the ability to trick a user into opening a malicious TIFF file could cause kfax to crash or possibly execute arbitrary code. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CVE-2004-0803 to this issue.
This update can be downloaded from: http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/
a104c3550141c3f0e7f5245e321f717d SRPMS/kdegraphics-3.2.2-1.1.src.rpm b9c227361354cebbcae97df082e60f3c x86_64/kdegraphics-3.2.2-1.1.x86_64.rpm bd4a9746410bae4f7c71bc4d3292777c x86_64/kdegraphics-devel-3.2.2-1.1.x86_64.rpm 247556c77e621e4fd67760f3ab818a13 x86_64/debug/kdegraphics-debuginfo-3.2.2-1.1.x86_64.rpm 1cc02d811b6a96d4382fe15e2b65a4cc i386/kdegraphics-3.2.2-1.1.i386.rpm 6f72f96c16132cac97501150bf6ddad7 i386/kdegraphics-devel-3.2.2-1.1.i386.rpm 1d7e317cb11d3ece70178be6f7f97215 i386/debug/kdegraphics-debuginfo-3.2.2-1.1.i386.rpm
This update can also be installed with the Update Agent you can launch the Update Agent with the 'up2date' command.
Solution: Apply the appropriate updates. http://www.fedoranews.org/updates/FEDORA-2004-357.shtml
Risk factor : Critical
CVSS Score: 10.0
|