Bug 175113

Summary: CVE-2005-3193 xpdf issues (CVE-2005-3191 CVE-2005-3192)
Product: [Fedora] Fedora Reporter: Josh Bressers <bressers>
Component: popplerAssignee: Kristian Høgsberg <krh>
Status: CLOSED CURRENTRELEASE QA Contact:
Severity: high Docs Contact:
Priority: medium    
Version: 4CC: djuran, security-response-team
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard: impact=important,reported=20051103,public=20051206
Fixed In Version: 0.4.3-1.3 Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2006-01-10 19:14:06 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description Josh Bressers 2005-12-06 18:06:19 UTC
+++ This bug was initially created as a clone of Bug #173888 +++

Derek Noonburg sent us a patch for xpdf to correct a number of security issues.
 This is due to be public 20051201.

An attacker could construct a carefully crafted PDF file that could cause Xpdf
to crash or possibly execute arbitrary code when opened. 

-- Additional comment from mjc on 2005-11-22 03:42 EST --
Created an attachment (id=121332)
Proposed patch from Derek

Comment 1 Josh Bressers 2005-12-06 18:56:25 UTC
Attachment 121940 [details] contains a more complete patch which was taken from our recent
xpdf update.

Comment 2 Fedora Update System 2005-12-08 20:51:11 UTC
From User-Agent: XML-RPC

poppler-0.4.1-1.2 has been pushed for FC4, which should resolve this issue.  If these problems are still present in this version, then please make note of it in this bug report.

Comment 3 Josh Bressers 2005-12-08 20:56:50 UTC
Please note that the original patch for this issue is incomplete.  I'll post
details of a complete patch once we have one.

Comment 4 Josh Bressers 2005-12-14 15:30:05 UTC
The patches for these issues are in attachment 122226 [details] and attachment 122227 [details].

The sooner we can have new packages rolled the better as the Christmas holiday
is quickly approaching.

Comment 5 Josh Bressers 2005-12-14 16:12:50 UTC
There aren't currently any reproducers for these issues.

Please note that these issues affect xpdf, kdegraphics, cups, gpdf, tetex and
poppler.  Some cooperation will probably make things easier.

Comment 6 Fedora Update System 2005-12-19 16:54:18 UTC
From User-Agent: XML-RPC

An update for FC4 has been released with a fix for this problem.  Package is poppler-0.4.3-1.3.