Bug 163924

Summary: gpdf DoS
Product: [Fedora] Fedora Reporter: Josh Bressers <bressers>
Component: gpdfAssignee: Marco Pesenti Gritti <mpg>
Status: CLOSED INSUFFICIENT_DATA QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: 3CC: mattdm, security-response-team
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard: impact=moderate,source=vendorsec,reported=20050721
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2008-02-12 01:25:56 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description Josh Bressers 2005-07-22 00:35:53 UTC
+++ This bug was initially created as a clone of Bug #163918 +++

A broken PDF file is will create a file in /tmp and continue to fill it until
the filesystem is full.

The patch for this issue is attachment 117043 [details]
The demo exploit for this issue is attachment 117042 [details]

Comment 1 Josh Bressers 2005-07-22 00:36:52 UTC
This issue also affects FC3

Comment 2 Josh Bressers 2005-07-22 00:37:41 UTC
err, this issue only affects FC3

Comment 3 Marco Pesenti Gritti 2005-07-25 08:03:17 UTC
For FC4 I think this apply to poppler instead.

Comment 4 Josh Bressers 2005-07-25 11:10:21 UTC
Marco,

I'm not sure if this issue affects poppler.  I can't get evince to fill up /tmp
when I open this PDF file (I know it's the same code, but for some reason it's
not crashing).

Comment 5 Mark J. Cox 2005-08-10 08:39:27 UTC
Removing embargo

Comment 6 Matthew Miller 2006-07-10 20:31:04 UTC
Fedora Core 3 is now maintained by the Fedora Legacy project for security
updates only. If this problem is a security issue, please reopen and
reassign to the Fedora Legacy product. If it is not a security issue and
hasn't been resolved in the current FC5 updates or in the FC6 test
release, reopen and change the version to match.

Thank you!


Comment 7 petrosyan 2008-02-12 01:25:56 UTC
Fedora Core 3 is not maintained anymore.

Setting status to "INSUFFICIENT_DATA". If you can reproduce this bug in the
current Fedora release, please reopen this bug and assign it to the
corresponding Fedora version.