Comment 1 for bug 240427

Revision history for this message
h1repp (heinz-repp) wrote :

Hello,

I just want to second this request and present further details why it would be worthy:

pdfedit is unrivaled when it comes to editing a pdf without any conversion to another format, doing all the work with the pdf objects themself.

The new version 0.4.1 has some major enhancements and security fixes as compared to the 0.3.2 that is in hardy repositories. The most significant part is that the version of xpdf that is compiled statically into the executable is so much newer, the one in the repositories is still vulnerable to the xpdf exploit from 2007. I quote from the version 0.4.0 announcement::

- many bug fixes (see Changelog) some of them security related.
- last 3.02 xpdf code base imported to the tree. This bring
some new features like anti-aliasing for vectored graphics,
support for PDF 1.6, 1.7 specification, security fixes and
many others (see src/xpdf/CHANGES for complete changelog)

Regarding hardy's LTS status it would be great if users had an option not to stick with its vulnerable version unable to work with newer pdfs for the next years.

Thank you

h1repp