Comment 4 for bug 11418

Revision history for this message
Debian Bug Importer (debzilla) wrote :

Message-ID: <email address hidden>
Date: Fri, 24 Dec 2004 08:27:46 +1100
From: Hamish Moffatt <email address hidden>
To: <email address hidden>, <email address hidden>
Subject: Re: Bug#286983: xpdf: Vulnerable to CAN-2004-1125

On Thu, Dec 23, 2004 at 01:51:27PM +0100, Martin Pitt wrote:
> xpdf is vulnerable to CAN-2004-1125, see
>
> http://www.idefense.com/application/poi/display?id=172
>
> for details.

Thanks for the note. I uploaded -11 yesterday morning with
the upstream author's patch applied. Bug#286742 was filed,
though against xpdf-reader so you may have missed it.

> You can get the Ubuntu security patch from
> http://patches.ubuntu.com/patches/xpdf.CAN-2004-1125.diff

It appears to be functionally equivalent to Derek's patch but
with some reformatting.

Regards
Hamish
--
Hamish Moffatt VK3SB <email address hidden> <email address hidden>