Description: | Description:
The remote host is missing updates announced in advisory FLSA-2006:175404.
A flaw was discovered in Xpdf in that an attacker could construct a carefully crafted PDF file that would cause Xpdf to consume all available disk space in /tmp when opened. The Common Vulnerabilities and Exposures project assigned the name CVE-2005-2097 to this issue.
Several flaws were discovered in Xpdf. An attacker could construct a carefully crafted PDF file that could cause Xpdf to crash or possibly execute arbitrary code when opened. The Common Vulnerabilities and Exposures project assigned the names CVE-2005-3191, CVE-2005-3192, CVE-2005-3193, CVE-2005-3624, CVE-2005-3625, CVE-2005-3626, CVE-2005-3627 and CVE-2005-3628 to these issues.
A heap based buffer overflow bug was discovered in Xpdf. An attacker could construct a carefully crafted PDF file that could cause Xpdf to crash or possibly execute arbitrary code when opened. The Common Vulnerabilities and Exposures project assigned the name CVE-2006-0301 to this issue.
Users of Xpdf should upgrade to this updated package, which contains backported patches to resolve these issues.
Affected platforms: Redhat 7.3 Redhat 9 Fedora Core 1 Fedora Core 2 Fedora Core 3
Solution: http://www.securityspace.com/smysecure/catid.html?in=FLSA-2006:175404
Risk factor : Critical
CVSS Score: 10.0
|