Solution
Please Install the Updated Packages.
Insight
Xpdf is an X Window System based viewer for Portable Document Format (PDF) files.
Multiple integer overflow flaws were found in Xpdf. An attacker could create a malicious PDF file that would cause Xpdf to crash or, potentially, execute arbitrary code when opened. (CVE-2009-0791, CVE-2009-3604, CVE-2009-3606, CVE-2009-3609)
Red Hat would like to thank Adam Zabrocki for reporting the CVE-2009-3604 issue.
Users are advised to upgrade to this updated package, which contains a backported patch to correct these issues.
Affected
xpdf on CentOS 3
References
Updated on 2015-03-25
Severity
Classification
-
CVE CVE-2009-0791, CVE-2009-3604, CVE-2009-3606, CVE-2009-3609 -
CVSS Base Score: 9.3
AV:N/AC:M/Au:N/C:C/I:C/A:C
Related Vulnerabilities