RHSA-2009:0431: Important security update
113
1.106.2. RHSA-2009:0431: Important security update
Important
This update has already been released (prior to the GA of this release) as the security
errata
RHSA-2009:0431
755
Updated kdegraphics packages that fix multiple security issues are now available for Red Hat
Enterprise Linux 4 and 5.
This update has been rated as having important security impact by the Red Hat Security Response
Team.
The kdegraphics packages contain applications for the K Desktop Environment, including KPDF, a
viewer for Portable Document Format (PDF) files.
Multiple integer overflow flaws were found in KPDF's JBIG2 decoder. An attacker could create a
malicious PDF file that would cause KPDF to crash or, potentially, execute arbitrary code when
opened. (
CVE-2009-0147
756
,
CVE-2009-1179
757
)
Multiple buffer overflow flaws were found in KPDF's JBIG2 decoder. An attacker could create a
malicious PDF file that would cause KPDF to crash or, potentially, execute arbitrary code when
opened. (
CVE-2009-0146
758
,
CVE-2009-1182
759
)
Multiple flaws were found in KPDF's JBIG2 decoder that could lead to the freeing of arbitrary memory.
An attacker could create a malicious PDF file that would cause KPDF to crash or, potentially, execute
arbitrary code when opened. (
CVE-2009-0166
760
,
CVE-2009-1180
761
)
Multiple input validation flaws were found in KPDF's JBIG2 decoder. An attacker could create a
malicious PDF file that would cause KPDF to crash or, potentially, execute arbitrary code when
opened. (
CVE-2009-0800
762
)
Multiple denial of service flaws were found in KPDF's JBIG2 decoder. An attacker could
create a malicious PDF that would cause KPDF to crash when opened. (
CVE-2009-0799
763
,
CVE-2009-1181
764
,
CVE-2009-1183
765
)
Red Hat would like to thank Braden Thomas and Drew Yao of the Apple Product Security team, and
Will Dormann of the CERT/CC for responsibly reporting these flaws.
Users are advised to upgrade to these updated packages, which contain backported patches to
resolve these issues.
756
https://www.redhat.com/security/data/cve/CVE-2009-0147.html
757
https://www.redhat.com/security/data/cve/CVE-2009-1179.html
758
https://www.redhat.com/security/data/cve/CVE-2009-0146.html
759
https://www.redhat.com/security/data/cve/CVE-2009-1182.html
760
https://www.redhat.com/security/data/cve/CVE-2009-0166.html
761
https://www.redhat.com/security/data/cve/CVE-2009-1180.html
762
https://www.redhat.com/security/data/cve/CVE-2009-0800.html
763
https://www.redhat.com/security/data/cve/CVE-2009-0799.html
764
https://www.redhat.com/security/data/cve/CVE-2009-1181.html
765
https://www.redhat.com/security/data/cve/CVE-2009-1183.html
Summary of Contents for ENTERPRISE 5.4 RELEASE NOTES
Page 1: ...Red Hat Enterprise Linux 5 4 Technical Notes Every Change to Every Package ...
Page 18: ...xviii ...
Page 306: ...288 ...
Page 464: ...446 ...
Page 466: ...448 ...