Comment 1 for bug 28034

Revision history for this message
Debian Bug Importer (debzilla) wrote :

Message-ID: <email address hidden>
Date: Thu, 5 Jan 2006 15:14:26 +0100
From: Martin Pitt <email address hidden>
To: Debian BTS Submit <email address hidden>
Cc: <email address hidden>
Subject: tetex-bin: New integer overflows in xpdf copy [CVE-2005-3624, CVE-2005-3625, CVE-2005-3627]

--H4SyuGOnfnj3aJqJ
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
Content-Transfer-Encoding: quoted-printable

Package: tetex-bin
Version: 2.0.2-30
Severity: critical
Tags: security patch

Hi!

Chris Evans found some more integer overflows in the xpdf code [1] which af=
fect
tetex-bin as well. [1] also has demo exploit PDFs for patch checking.

See [2] for the Ubuntu debdiff.=20

This only affects sarge (and woody); luckily sid is finally cured
forever due to poppler, so please mark this bug as fixed in sid.

Thanks,

Martin

[1] http://scary.beasts.org/security/b0dfca810501f2da/CESA-2005-003.txt
[2] http://patches.ubuntu.com/patches/tetex-bin.CVE-2005-3624_5_7.diff

--=20
Martin Pitt http://www.piware.de
Ubuntu Developer http://www.ubuntu.com
Debian Developer http://www.debian.org

In a world without walls and fences, who needs Windows and Gates?

--H4SyuGOnfnj3aJqJ
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: Digital signature
Content-Disposition: inline

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.2 (GNU/Linux)

iD8DBQFDvSnCDecnbV4Fd/IRAj10AJ9NWypK8/rbH60s+SfriDgN1/yLPACgrqPR
GZ9uTjQ3A0XL7IVQqcLopw8=
=sPGr
-----END PGP SIGNATURE-----

--H4SyuGOnfnj3aJqJ--