Bug 175107

Summary: CVE-2005-3193 xpdf issues (CVE-2005-3191 CVE-2005-3192)
Product: [Fedora] Fedora Reporter: Josh Bressers <bressers>
Component: kdegraphicsAssignee: Than Ngo <than>
Status: CLOSED ERRATA QA Contact:
Severity: high Docs Contact:
Priority: medium    
Version: 4CC: rdieter, security-response-team
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard: impact=important,reported=20051103,public=20051206
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2006-01-16 16:10:25 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description Josh Bressers 2005-12-06 17:50:54 UTC
+++ This bug was initially created as a clone of Bug #175105 +++

+++ This bug was initially created as a clone of Bug #175089 +++

Derek Noonburg sent us a patch for xpdf to correct a number of security issues.
 This is due to be public 20051201.

An attacker could construct a carefully crafted PDF file that could cause Xpdf
to crash or possibly execute arbitrary code when opened. 

This issue affects RHEL3, RHEL3, RHEL2.1

-- Additional comment from mjc on 2005-11-22 03:42 EST --
Created an attachment (id=121332)
Proposed patch from Derek


This issue also affects FC3

Comment 1 Josh Bressers 2005-12-06 18:56:40 UTC
Attachment 121940 [details] contains a more complete patch which was taken from our recent
xpdf update.

Comment 2 Josh Bressers 2005-12-14 15:30:21 UTC
The patches for these issues are in attachment 122226 [details] and attachment 122227 [details].

The sooner we can have new packages rolled the better as the Christmas holiday
is quickly approaching.

Comment 3 Josh Bressers 2005-12-14 16:13:11 UTC
There aren't currently any reproducers for these issues.

Please note that these issues affect xpdf, kdegraphics, cups, gpdf, tetex and
poppler.  Some cooperation will probably make things easier.

Comment 4 Than Ngo 2006-01-16 15:58:56 UTC
*** Bug 176246 has been marked as a duplicate of this bug. ***

Comment 5 Than Ngo 2006-01-16 16:10:25 UTC
it's now fixed in kdegraphics-3.5.0-0.2.fc4 (FC4), kdegraphics-3.4.2-0.fc3.3 (FC3)