Changelog
xpdf (3.02-1.4+lenny2) stable-security; urgency=high
* Non-maintainer upload by the Security Team.
* Fixes multiple security issues (Closes: #551287):
- CVE-2009-1188 and CVE-2009-3603:
Integer overflow in SplashBitmap::SplashBitmap which might allow remote
attackers to execute arbitrary code or an application crash via a crafted
PDF document.
- CVE-2009-3604:
NULL pointer dereference or heap-based buffer overflow in
Splash::drawImage which might allow remote attackers to cause a denial of
service (application crash) or possibly execute arbitrary code via a
crafted PDF document.
- CVE-2009-3606:
Integer overflow in the PSOutputDev::doImageL1Sep which might allow
remote attackers to execute arbitrary code via a crafted PDF document.
- CVE-2009-3608:
Integer overflow in the ObjectStream::ObjectStream which might allow
remote attackers to execute arbitrary code via a crafted PDF document.
- CVE-2009-3609:
Integer overflow in the ImageStream::ImageStream which might allow
remote attackers to cause a denial of service via a crafted PDF
document.
-- Luciano Bello <email address hidden> Mon, 22 Mar 2010 17:07:50 -0300