|
|
>> Fedora Security Update Fixes Xpdf Buffer Overflow Vulnerabilities
|
Title : Fedora Security Update Fixes Xpdf Buffer Overflow Vulnerabilities VUPEN ID : VUPEN/ADV-2005-2954 CVE ID : CVE-2005-3193
Rated as : High Risk 
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2005-12-19
|
Fedora has released updated packages to correct multiple vulnerabilities identified in xpdf. These flaws could be exploited by remote attackers to execute arbitrary commands and take complete control of an affected system. For additional information, see : VUPEN/ADV-2005-2755
Affected Products
Fedora Core 3
Fedora Core 4
Solution
Upgrade the affected packages :
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/3/
3fbdcffe2a17515fca487c822e8ba898 SRPMS/xpdf-3.01-0.FC3.4.src.rpm
942fbe93c401ef2af4df6f78a0f171a8 x86_64/xpdf-3.01-0.FC3.4.x86_64.rpm
2fccaa6ad73c1ee153c5b0c80778f481 x86_64/debug/xpdf-debuginfo-3.01-0.FC3.4.x86_64.rpm
a4f2424c0983090281229e8709f011bd i386/xpdf-3.01-0.FC3.4.i386.rpm
cf9f51b46f0a56818577d58a42f24856 i386/debug/xpdf-debuginfo-3.01-0.FC3.4.i386.rpm
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/4/
8eb2b8dde353ab48730c89972991a2fc SRPMS/xpdf-3.01-0.FC4.5.src.rpm
012186b96a434e36c7b04bdda865e8e5 ppc/xpdf-3.01-0.FC4.5.ppc.rpm
c43973989dae59251a1f6f2ea1c3596e ppc/debug/xpdf-debuginfo-3.01-0.FC4.5.ppc.rpm
9e70f7a2df42688105546aca78da6faf x86_64/xpdf-3.01-0.FC4.5.x86_64.rpm
7eaf3e7bda92dd7ab210de5f103a12cf x86_64/debug/xpdf-debuginfo-3.01-0.FC4.5.x86_64.rpm
4ec1702606e69f0aea8265951e6bd83d i386/xpdf-3.01-0.FC4.5.i386.rpm
effbf4cfdbb8284d4963a1d9db0270a3 i386/debug/xpdf-debuginfo-3.01-0.FC4.5.i386.rpm
References
http://www.vupen.com/english/advisories/2005/2954 http://www.frsirt.com/english/reference/2827 http://www.frsirt.com/english/reference/2828
ChangeLog
2005-12-19 : Initial release
Vulnerability Management
Subscribe to VUPEN VNS and receive real-time alerts when new advisories or patches relevant to your systems and network configurations are available.
Feedback
If you have additional information or corrections for this security advisory please submit them via our contact form. | |
|