Apache OpenOffice (AOO) Bugzilla – Issue 101156
xpdf security-buggy
Last modified: 2009-04-29 14:34:51 UTC
[ afais also in 3.1 ] http://rhn.redhat.com/errata/RHSA-2009-0430.html --- snip --- Multiple integer overflow flaws were found in Xpdf's JBIG2 decoder. An attacker could create a malicious PDF file that would cause Xpdf to crash or, potentially, execute arbitrary code when opened. (CVE-2009-0147, CVE-2009-1179) Multiple buffer overflow flaws were found in Xpdf's JBIG2 decoder. An attacker could create a malicious PDF file that would cause Xpdf to crash or, potentially, execute arbitrary code when opened. (CVE-2009-0146, CVE-2009-1182) Multiple flaws were found in Xpdf's JBIG2 decoder that could lead to the freeing of arbitrary memory. An attacker could create a malicious PDF file that would cause Xpdf to crash or, potentially, execute arbitrary code when opened. (CVE-2009-0166, CVE-2009-1180) Multiple input validation flaws were found in Xpdf's JBIG2 decoder. An attacker could create a malicious PDF file that would cause Xpdf to crash or, potentially, execute arbitrary code when opened. (CVE-2009-0800) Multiple denial of service flaws were found in Xpdf's JBIG2 decoder. An attacker could create a malicious PDF that would cause Xpdf to crash when opened. (CVE-2009-0799, CVE-2009-1181, CVE-2009-1183) --- snip ---
change component
.
brought xpdf up to 3.02pl3 including the JBIG changes (see ftp://ftp.foolabs.com/pub/xpdf/xpdf-3.02pl3.patch)
please verify in CWS rnwinr01
Verified in CWS.
Closed.