Oval Definition:oval:com.redhat.rhsa:def:20050066
Revision Date:2005-02-15Version:502
Title:RHSA-2005:066: kdegraphics security update (Important)
Description:The kdegraphics packages contain applications for the K Desktop Environment including kpdf, a pdf file viewer.

A buffer overflow flaw was found in the Gfx::doImage function of Xpdf that also affects kpdf due to a shared codebase. An attacker could construct a carefully crafted PDF file that could cause kpdf to crash or possibly execute arbitrary code when opened. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CAN-2004-1125 to this issue.

A buffer overflow flaw was found in the Decrypt::makeFileKey2 function of Xpdf which also affects kpdf due to a shared codebase. An attacker could construct a carefully crafted PDF file that could cause kpdf to crash or possibly execute arbitrary code when opened. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CAN-2005-0064 to this issue.

During a source code audit, Chris Evans and others discovered a number of integer overflow bugs that affected all versions of Xpdf which also affects kpdf due to a shared codebase. An attacker could construct a carefully crafted PDF file that could cause kpdf to crash or possibly execute arbitrary code when opened. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CAN-2004-0888 to this issue.

Users should update to these erratum packages which contain backported patches to correct these issues.
Family:unixClass:patch
Status:Reference(s):CVE-2004-0888
CVE-2004-1125
CVE-2005-0064
RHSA-2005:066-01
Platform(s):Red Hat Enterprise Linux 4
Product(s):
Definition Synopsis
  • Red Hat Enterprise Linux 4 is installed
  • AND Package Information
  • kdegraphics is earlier than 7:3.3.1-3.3
  • AND kdegraphics is signed with Red Hat master key
  • OR
  • kdegraphics-devel is earlier than 7:3.3.1-3.3
  • AND kdegraphics-devel is signed with Red Hat master key
  • BACK