Bug 147518
Summary: | CAN-2004-0888 xpdf integer overflows | ||
---|---|---|---|
Product: | Red Hat Enterprise Linux 4 | Reporter: | Josh Bressers <bressers> |
Component: | gpdf | Assignee: | Marco Pesenti Gritti <mpg> |
Status: | CLOSED ERRATA | QA Contact: | |
Severity: | high | Docs Contact: | |
Priority: | medium | ||
Version: | 4.0 | Keywords: | Security |
Target Milestone: | --- | ||
Target Release: | --- | ||
Hardware: | All | ||
OS: | Linux | ||
Whiteboard: | impact=important,public=20041020 | ||
Fixed In Version: | Doc Type: | Bug Fix | |
Doc Text: | Story Points: | --- | |
Clone Of: | Environment: | ||
Last Closed: | 2005-02-15 10:15:24 UTC | Type: | --- |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: |
Description
Josh Bressers
2005-02-08 18:42:43 UTC
The original fix for this issue was incomplete. Please see bug 135393 for a proper fix. Now that I look at this, I don't think we've fixed this at all in RHEL4. That fix is upstream in 2.8.2, that's why we have no patch for it. I looked at the code and I'm not seeing a fix for this issue. If I'm missing something please point it out. >Now that I look at this, I don't think we've fixed this at all in RHEL4. I was referring to this comment. The original patch for CAN-2004-0888 is actually in the 2.8.2 sources. This is in the Changelog and I verified I can patch -R it. 2004-11-05 Dan Williams <dcbw> * xpdf/Catalog.cc, xpdf/XRef.cc: Fix for a number of integer overflow bugs discovered by Chris Evans. CAN-2004-0888, Bug #156729, Red Hat Bug #137420. We still need to fix the issue discovered with that patch. I have that almost done. Ok I built gpdf-2.8.2-4.3 with the patch and updated the errata files. An advisory has been issued which should help the problem described in this bug report. This report is therefore being closed with a resolution of ERRATA. For more information on the solution and/or where to find the updated files, please follow the link below. You may reopen this bug report if the solution does not work for you. http://rhn.redhat.com/errata/RHSA-2005-057.html |