Bug 216850 - app-text/poppler <0.6.3 xpdf Object embedded font function dereference (CVE-2008-1693)
|
Bug#:
216850
|
Product: Gentoo Security
|
Version: unspecified
|
Platform: All
|
|
OS/Version: Linux
|
Status: RESOLVED
|
Severity: major
|
Priority: P2
|
|
Resolution: FIXED
|
Assigned To: security@gentoo.org
|
Reported By: rbu@gentoo.org
|
|
Component: Vulnerabilities
|
|
|
URL:
|
|
Summary: app-text/poppler <0.6.3 xpdf Object embedded font function dereference (CVE-2008-1693)
|
|
Keywords:
|
|
Status Whiteboard: A2 [glsa]
|
|
Opened: 2008-04-08 10:04 0000
|
xpdf / poppler does not type-check the the "stream" object before dereferencing
a function from it, allowing for arbitrary code execution via pdf files with
embedded fonts.
We have quite some places where this needs fixing. Embargo date is April, 15
currently.
I'm waiting for some indication of how to fix this...
dang, anything that can be done about bug 201448 beforehand?
As it seems, neither KPDF nor TeX are affected, because both had the
cairo-related code paths removed.
I'll take a look. I don't have anything with qt, so it will take a bit.
Probably a good idea to test and mark app-text/poppler-bindings-0.6.3 stable in
the same go.
Stable for HPPA:
=app-text/poppler-0.6.3
=app-text/poppler-bindings-0.6.3
Anything else? :)
alpha/ia64/sparc/x86 stable
ppc stable (proxy commit for dertobi123)
Lifting embargo since the agreed date has passed.
Arches, please test and mark stable:
=app-text/poppler-0.6.3
Target keywords : "alpha amd64 arm hppa ia64 m68k ppc ppc64 release s390 sh
sparc x86"
Already stabled : "alpha amd64 hppa ia64 ppc ppc64 sparc x86"
Missing keywords: "arm m68k release s390 sh"
Fixed in release snapshot.
*** Bug 221297 has been marked as a duplicate of this bug. ***