Linux Compatible
  • News
    • Channels
    • Archive
    • Search
    • Submit
  • Articles
    • Categories
  • Knowledgebase
  • Compatibility
    • Search
  • Links
  • Forums
  • Twitter
Advertisement

Latest News
[ Windows | Linux | Apple ]

· Update for Windows 8/Server 2012
· Apple TV 5.4 beta adds iTunes Radio, Conference Room Display
· DSA 2710-1: xml-security-c security update
· Intel DZ87KLT-75K Kinsley Thunderbolt Motherboard Review
· Microsoft launches Surface RT discount for schools
· MacStadium to provide new Mac Pro hosting and colocation
· Netflix outside the USA - in Linux & with Tunlr
· Enhanced Mitigation Experience Toolkit 4.0
· Intel Haswell HD Graphics 4600 vs. AMD Radeon Graphics On Linux
· DSA 2709-1: wireshark security update

Upcoming News
· OCZ Vertex 450 256GB SSD Review @ Hardware Canucks
· ASUS Z87-PRO Motherboard Review @ HiTech Legion
· REVIEW: Cooler Master Seidon 240M @ PureOverclock
· NVIDIA Announces It Will Its License Graphics IP, Goes After PowerVR
· ANNOUNCE: AT-SPI 2.9.3 released
· Mutter 3.9.3
· GNOME Shell 3.9.3
· Microsoft Responds on Fake Xbox One E3 Demo Story
· [Tech ARP] The Linux Kernel As An Exquisitely Sensitive Stability Test For Overclocked Systems
· Zowie FK Gaming Mouse Review

Linux Compatibility
· Dell Dimension 9100
· CL-CAM50001 UPC=3700284609322
· DFE 520 TX
· nVidia GeForce4 MX 440
· Gore: Ultimate Soldier
· SMC2802W V2 wi-fi 54Mbps PCI card
· Wireless modem router N300
· Dell P780
· ASUS A7V8X
· BricsCAD for Linux

New Forum Topics
· Building a new PC: how EXACTLY to install USB mouse?
by: joyask43
on: 2013-06-09 14:36
6 replies, 2633 views

· Packet CD
by: natalieksh5
on: 2013-06-06 14:19
4 replies, 3445 views

· THE SIMS 2 DIRECTX 9.0C ERROR MESSAGE!! HELP! URGENT!!
by: tandrask34
on: 2013-06-05 14:06
28 replies, 93196 views

· Hello
by: barryherne
on: 2013-06-05 13:09
0 replies, 179 views

· shutdown link ?
by: estirwent
on: 2013-05-11 17:46
18 replies, 6892 views

News Channels
· Drivers
· Guides
· Reviews
· Security
· Software
· Press Release
· Updates
· Interviews
· Linux
· General
· Debian
· Red Hat
· Slackware
· Gentoo
· Mandriva
· White Box
· SUSE
· GNOME
· KDE
· CentOS
· Ubuntu
· MEPIS
· Android

What's New
Login to see an overview of all news stories since your last visit.

Welcome to our website

To take full advantage of all features you need to login or register. Registration is completely free and takes only a few seconds.

Linux Compatible » News » January 2006 » [KDE Security Advisory] UPDATE: kpdf/xpdf multiple integer overflow

[KDE Security Advisory] UPDATE: kpdf/xpdf multiple integer overflow

Posted by Philipp Esselbach on: 01/04/2006 04:50 PM [ Print | 0 comment(s) ]

KDE Security Advisory [UPDATED]: kpdf/xpdf multiple integer overflows
Original Release Date: 2005-12-07
Final Release Date: 2006-01-03
URL: http://www.kde.org/info/security/advisory-20051207-2.txt

0. References
CAN-2005-3191
CAN-2005-3192
CAN-2005-3193
CVE-2005-3624
CVE-2005-3625
CVE-2005-3626
CVE-2005-3627
CESA-2005-003

1. Systems affected:

KDE 3.2.0 up to including KDE 3.5.0
KOffice 1.3.0 up to including KOffice 1.4.2




2. Overview:

kpdf, the KDE pdf viewer, shares code with xpdf. xpdf contains
multiple integer overflow vulnerabilities that allow specially
crafted pdf files, when opened, to overflow heap allocated
buffers and execute arbitrary code.

The patches announced in the KDE security advisory 20051207-1
were incomplete. This re-issued advisory contains updated patches
that correct issues with the original upstream patch that were
found and fixed by Ludwig Nussel, Martin Pitt and Chris Evans.
The previous patches and advisory have been removed.

3. Impact:

Remotely supplied pdf files can be used to execute arbitrary
code on the client machine.

4. Solution:

Source code patches have been made available which fix these
vulnerabilities. Contact your OS vendor / binary package provider
for information about how to obtain updated binary packages.

5. Patch:

Patch for KDE 3.5.0 is available from
ftp://ftp.kde.org/pub/kde/security_patches :

17ea076e986be5e26a4feea3cd264f7e
post-3.5.0-kdegraphics-CAN-2005-3193.diff

Patch for KDE 3.4.3 is available from
ftp://ftp.kde.org/pub/kde/security_patches :

e8dde74416769d4589dcca25072aea3e
post-3.4.3-kdegraphics-CAN-2005-3193.diff

Patch for KDE 3.3.2 is available from
ftp://ftp.kde.org/pub/kde/security_patches :

fe38b0728e5e2b000eb04e037536f330
post-3.3.2-kdegraphics-CAN-2005-3193.diff

Patch for KDE 3.2.3 is available from
ftp://ftp.kde.org/pub/kde/security_patches :

51ae90242b7e65ba34c704b38c91cfbe
post-3.2.3-kdegraphics-CAN-2005-3193.diff

Patch for KOffice 1.3.0 and newer is available from
ftp://ftp.kde.org/pub/kde/security_patches :

939b41e59cfb5f738e9b6fcfff4faf48
post-1.3-koffice-CAN-2005-3193.diff


Bookmark and Share

« Wait for Windows patch opens attack window · VIA HyperionPro 4in1 Driver 5.07a »

Linux Compatible » News » January 2006 » [KDE Security Advisory] UPDATE: kpdf/xpdf multiple integer overflow
All products mentioned are registered trademarks or trademarks of their respective owners.
© 2002-2013 Esselbach Internet Solutions - All Rights Reserved. Terms and privacy policy
Powered by Contentteller® Business Edition