Lucene search

K
osvGoogleOSV:DSA-932-1
HistoryJan 09, 2006 - 12:00 a.m.

kdegraphics - buffer overflows

2006-01-0900:00:00
Google
osv.dev
19

0.184 Low

EPSS

Percentile

96.2%

“infamous41md” and Chris Evans discovered several heap based buffer
overflows in xpdf, the Portable Document Format (PDF) suite, that can
lead to a denial of service by crashing the application or possibly to
the execution of arbitrary code. The same code is present in kpdf
which is part of the kdegraphics package.

The old stable distribution (woody) does not contain kpdf packages.

For the stable distribution (sarge) these problems have been fixed in
version 3.3.2-2sarge3.

For the unstable distribution (sid) these problems have been fixed in
version 3.5.0-3.

We recommend that you upgrade your kpdf package.