Revision Date: | 2013-04-29 | Version: | 12 | Title: | Integer overflow in the ObjectStream::ObjectStream function in XRef.cc in Xpdf 3.x before 3.02pl4 and Poppler before 0.12.1, as used in GPdf, kdegraphics KPDF, CUPS pdftops, and teTeX, might allow remote attackers to execute arbitrary code via a crafted PDF document that triggers a heap-based buffer overflow. | Description: | Integer overflow in the ObjectStream::ObjectStream function in XRef.cc in Xpdf 3.x before 3.02pl4 and Poppler before 0.12.1, as used in GPdf, kdegraphics KPDF, CUPS pdftops, and teTeX, might allow remote attackers to execute arbitrary code via a crafted PDF document that triggers a heap-based buffer overflow. | Family: | unix | Class: | vulnerability | Status: | ACCEPTED | Reference(s): | CVE-2009-3608
| Platform(s): | CentOS Linux 4 CentOS Linux 5 Oracle Linux 4 Oracle Linux 5 Red Hat Enterprise Linux 4 Red Hat Enterprise Linux 5
| Product(s): | | Definition Synopsis | OS Section: RHEL4, CentOS4, Oracle Linux 4 RHEL4, CentOS4 or Oracle Linux 4
The operating system installed on the system is Red Hat Enterprise Linux 4
OR CentOS Linux 4.x
OR Oracle Linux 4.x
AND Configuration section
kdegraphics-devel is earlier than 7:3.3.1-15.el4_8.2
OR gpdf is earlier than 0:2.8.2-7.7.2.el4_8.5
OR xpdf is earlier than 1:3.00-22.el4_8.1
OR kdegraphics is earlier than 7:3.3.1-15.el4_8.2
OR OS Section: RHEL5, CentOS5, Oracle Linux 5
RHEL5, CentOS5 or Oracle Linux 5
The operating system installed on the system is Red Hat Enterprise Linux 5
OR The operating system installed on the system is CentOS Linux 5.x
OR Oracle Linux 5.x
AND Configuration section
kdegraphics-devel is earlier than 7:3.5.4-15.el5_4.2
OR cups-lpd is earlier than 1:1.3.7-11.el5_4.3
OR tetex-dvips is earlier than 0:3.0-33.8.el5_5.5
OR kdegraphics is earlier than 7:3.5.4-15.el5_4.2
OR poppler is earlier than 0:0.5.4-4.4.el5_4.11
OR tetex-fonts is earlier than 0:3.0-33.8.el5_5.5
OR cups-libs is earlier than 1:1.3.7-11.el5_4.3
OR tetex is earlier than 0:3.0-33.8.el5_5.5
OR tetex-doc is earlier than 0:3.0-33.8.el5_5.5
OR poppler-devel is earlier than 0:0.5.4-4.4.el5_4.11
OR tetex-latex is earlier than 0:3.0-33.8.el5_5.5
OR poppler-utils is earlier than 0:0.5.4-4.4.el5_4.11
OR cups-devel is earlier than 1:1.3.7-11.el5_4.3
OR tetex-afm is earlier than 0:3.0-33.8.el5_5.5
OR tetex-xdvi is earlier than 0:3.0-33.8.el5_5.5
OR cups is earlier than 1:1.3.7-11.el5_4.3
|
|