Description: | Summary: The remote host is missing an update for the 'xpdf/poppler/koffice/kdegraphics' package(s) announced via the SSA:2007-316-01 advisory.
Vulnerability Insight: New xpdf packages are available for Slackware 9.1, 10.0, 10.1, 10.2, 11.0, 12.0, and -current. New poppler packages are available for Slackware 12.0 and -current. New koffice packages are available for Slackware 11.0, 12.0, and -current. New kdegraphics packages are available for Slackware 10.2, 11.0, 12.0, and -current.
These updated packages address similar bugs which could be used to crash applications linked with poppler or that use code from xpdf through the use of a malformed PDF document. It is possible that a maliciously crafted document could cause code to be executed in the context of the user running the application processing the PDF.
These advisories and CVE entries cover the bugs: [links moved to references]
Here are the details from the Slackware 12.0 ChangeLog: +--------------------------+ patches/packages/kdegraphics-3.5.7-i486-2_slack12.0.tgz: Patched xpdf related bugs. For more information, see: [links moved to references] (* Security fix *) patches/packages/koffice-1.6.3-i486-2_slack12.0.tgz: Patched xpdf related bugs. For more information, see: [links moved to references] (* Security fix *) patches/packages/poppler-0.6.2-i486-1_slack12.0.tgz: Upgraded to poppler-0.6.2. This release fixes xpdf related bugs. For more information, see: [links moved to references] (* Security fix *) patches/packages/xpdf-3.02pl2-i486-1_slack12.0.tgz: Upgraded to xpdf-3.02pl2. The pl2 patch fixes a crash in xpdf. Some theorize that this could be used to execute arbitrary code if an untrusted PDF file is opened, but no real-world examples are known (yet). For more information, see: [links moved to references] (* Security fix *) +--------------------------+
Affected Software/OS: 'xpdf/poppler/koffice/kdegraphics' package(s) on Slackware 9.1, Slackware 10.0, Slackware 10.1, Slackware 10.2, Slackware 11.0, Slackware 12.0, Slackware current.
Solution: Please install the updated package(s).
CVSS Score: 9.3
CVSS Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C
|