![]() |
Home ▼ Bookkeeping
Online ▼ Security
Audits ▼
Managed
DNS ▼
About
Order
FAQ
Acceptable Use Policy
Dynamic DNS Clients
Configure Domains Dyanmic DNS Update Password Network
Monitor ▼
Enterprise Package
Advanced Package
Standard Package
Free Trial
FAQ
Price/Feature Summary
Order/Renew
Examples
Configure/Status Alert Profiles | ||
Test ID: | 1.3.6.1.4.1.25623.1.0.66113 |
Category: | Ubuntu Local Security Checks |
Title: | Ubuntu: Security Advisory (USN-850-2) |
Summary: | The remote host is missing an update for the 'poppler' package(s) announced via the USN-850-2 advisory. |
Description: | Summary: The remote host is missing an update for the 'poppler' package(s) announced via the USN-850-2 advisory. Vulnerability Insight: USN-850-1 fixed vulnerabilities in poppler. The security fix for CVE-2009-3605 introduced a regression that would cause certain applications, such as Okular, to segfault when opening certain PDF files. This update fixes the problem. We apologize for the inconvenience. Original advisory details: It was discovered that poppler contained multiple security issues when parsing malformed PDF documents. If a user or automated system were tricked into opening a crafted PDF file, an attacker could cause a denial of service or execute arbitrary code with privileges of the user invoking the program. Affected Software/OS: 'poppler' package(s) on Ubuntu 6.06, Ubuntu 8.04, Ubuntu 8.10, Ubuntu 9.04. Solution: Please install the updated package(s). CVSS Score: 6.8 CVSS Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P |
Cross-Ref: |
Common Vulnerability Exposure (CVE) ID: CVE-2009-3605 1021706 http://sunsolve.sun.com/search/document.do?assetkey=1-77-1021706.1-1 274030 http://sunsolve.sun.com/search/document.do?assetkey=1-66-274030-1 37114 http://secunia.com/advisories/37114 MDVSA-2009:334 http://www.mandriva.com/security/advisories?name=MDVSA-2009:334 MDVSA-2011:175 http://www.mandriva.com/security/advisories?name=MDVSA-2011:175 SUSE-SR:2009:018 http://lists.opensuse.org/opensuse-security-announce/2009-11/msg00004.html USN-850-1 http://www.ubuntu.com/usn/USN-850-1 http://cgit.freedesktop.org/poppler/poppler/commit/?id=284a92899602daa4a7f429e61849e794569310b5 http://cgit.freedesktop.org/poppler/poppler/commit/?id=7b2d314a61fd0e12f47c62996cb49ec0d1ba747a http://cgit.freedesktop.org/poppler/poppler/commit/?id=9cf2325fb22f812b31858e519411f57747d39bd8 https://bugs.launchpad.net/bugs/cve/2009-3605 https://bugzilla.redhat.com/show_bug.cgi?id=491840 https://launchpad.net/ubuntu/+archive/primary/+files/poppler_0.10.5-1ubuntu2.4.diff.gz https://launchpad.net/ubuntu/+archive/primary/+files/poppler_0.8.7-1ubuntu0.4.diff.gz oval:org.mitre.oval:def:7731 https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7731 |
Copyright | Copyright (C) 2009 Greenbone AG |
This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit. To run a free test of this vulnerability against your system, register below. |