Executive Summary
| Summary | |
|---|---|
| Title | kdegraphics security update |
| Informations | |||
|---|---|---|---|
| Name | RHSA-2009:0431 | First vendor Publication | 2009-04-16 |
| Vendor | RedHat | Last vendor Modification | 2009-04-16 |
| Severity (Vendor) | Important | Revision | 01 |
Security-Database Scoring CVSS v2
| Cvss vector : (AV:N/AC:L/Au:N/C:P/I:P/A:P) | |||
|---|---|---|---|
| Cvss Base Score | 7.5 | Attack Range | Network |
| Cvss Impact Score | 6.4 | Attack Complexity | Low |
| Cvss Expoit Score | 10 | Authentification | None Required |
| Calculate full CVSS 2.0 Vectors scores | |||
Detail
Problem Description: Updated kdegraphics packages that fix multiple security issues are now available for Red Hat Enterprise Linux 4 and 5. This update has been rated as having important security impact by the Red Hat Security Response Team. 2. Relevant releases/architectures: RHEL Desktop Workstation (v. 5 client) - i386, x86_64 RHEL Optional Productivity Applications (v. 5 server) - i386, x86_64 Red Hat Enterprise Linux AS version 4 - i386, ia64, ppc, s390, s390x, x86_64 Red Hat Enterprise Linux Desktop (v. 5 client) - i386, x86_64 Red Hat Enterprise Linux Desktop version 4 - i386, x86_64 Red Hat Enterprise Linux ES version 4 - i386, ia64, x86_64 Red Hat Enterprise Linux WS version 4 - i386, ia64, x86_64 3. Description: The kdegraphics packages contain applications for the K Desktop Environment, including KPDF, a viewer for Portable Document Format (PDF) files. Multiple integer overflow flaws were found in KPDF's JBIG2 decoder. An attacker could create a malicious PDF file that would cause KPDF to crash or, potentially, execute arbitrary code when opened. (CVE-2009-0147, CVE-2009-1179) Multiple buffer overflow flaws were found in KPDF's JBIG2 decoder. An attacker could create a malicious PDF file that would cause KPDF to crash or, potentially, execute arbitrary code when opened. (CVE-2009-0146, CVE-2009-1182) Multiple flaws were found in KPDF's JBIG2 decoder that could lead to the freeing of arbitrary memory. An attacker could create a malicious PDF file that would cause KPDF to crash or, potentially, execute arbitrary code when opened. (CVE-2009-0166, CVE-2009-1180) Multiple input validation flaws were found in KPDF's JBIG2 decoder. An attacker could create a malicious PDF file that would cause KPDF to crash or, potentially, execute arbitrary code when opened. (CVE-2009-0800) Multiple denial of service flaws were found in KPDF's JBIG2 decoder. An attacker could create a malicious PDF that would cause KPDF to crash when opened. (CVE-2009-0799, CVE-2009-1181, CVE-2009-1183) Red Hat would like to thank Braden Thomas and Drew Yao of the Apple Product Security team, and Will Dormann of the CERT/CC for responsibly reporting these flaws. Users are advised to upgrade to these updated packages, which contain backported patches to resolve these issues. 4. Solution: Before applying this update, make sure that all previously-released errata relevant to your system have been applied. This update is available via Red Hat Network. Details on how to use the Red Hat Network to apply this update are available at http://kbase.redhat.com/faq/docs/DOC-11259 5. Bugs fixed (http://bugzilla.redhat.com/): 490612 - CVE-2009-0146 xpdf: Multiple buffer overflows in JBIG2 decoder (setBitmap, readSymbolDictSeg) 490614 - CVE-2009-0147 xpdf: Multiple integer overflows in JBIG2 decoder 490625 - CVE-2009-0166 xpdf: Freeing of potentially uninitialized memory in JBIG2 decoder 491864 - Multiple PDF flaws 495886 - CVE-2009-0799 PDF JBIG2 decoder OOB read 495887 - CVE-2009-0800 PDF JBIG2 multiple input validation flaws 495889 - CVE-2009-1179 PDF JBIG2 integer overflow 495892 - CVE-2009-1180 PDF JBIG2 invalid free() 495894 - CVE-2009-1181 PDF JBIG2 NULL dereference 495896 - CVE-2009-1182 PDF JBIG2 MMR decoder buffer overflows 495899 - CVE-2009-1183 PDF JBIG2 MMR infinite loop DoS |
Original Source
| Url : https://rhn.redhat.com/errata/RHSA-2009-0431.html |
CWE : Common Weakness Enumeration
| id | Name |
|---|---|
| CWE-399 | Resource Management Errors |
| CWE-119 | Failure to Constrain Operations within the Bounds of a Memory Buffer |
| CWE-189 | Numeric Errors |
| CWE-20 | Improper Input Validation |
OVAL Definitions
CPE : Common Platform Enumeration
Open Source Vulnerability Database (OSVDB)
| id | Description |
|---|---|
| 54496 | Xpdf JBIG2 Decoder PDF File Handling Multiple Function Overflows |
| 54495 | CUPS JBIG2 Decoder PDF File Handling Multiple Function Overflows |
| 54489 | Xpdf JBIG2 Decoder PDF File Handling Unitialized Memory Free DoS |
| 54488 | CUPS JBIG2 Decoder PDF File Handling Unitialized Memory Free DoS |
| 54487 | Poppler JBIG2 Decoder PDF File Handling Out-of-bounds Read DoS |
| 54486 | Xpdf JBIG2 Decoder PDF File Handling Out-of-bounds Read DoS |
| 54485 | CUPS JBIG2 Decoder PDF File Handling Out-of-bounds Read DoS |
| 54484 | Poppler JBIG2 Decoder PDF File Handling NULL Dereference DoS |
| 54483 | Xpdf JBIG2 Decoder PDF File Handling NULL Dereference DoS |
| 54482 | CUPS JBIG2 Decoder PDF File Handling NULL Dereference DoS |
| 54481 | Poppler JBIG2 Decoder PDF File Handling Invalid Free Arbitrary Code Execution |
| 54480 | Xpdf JBIG2 Decoder PDF File Handling Invalid Free Arbitrary Code Execution |
| 54479 | CUPS JBIG2 Decoder PDF File Handling Invalid Free Arbitrary Code Execution |
| 54478 | Poppler JBIG2 Decoder PDF File Handling Unspecified Integer Overflow |
| 54477 | Xpdf JBIG2 Decoder PDF File Handling Unspecified Integer Overflow |
| 54476 | CUPS JBIG2 Decoder PDF File Handling Unspecified Integer Overflow |
| 54473 | Poppler JBIG2 Decoder PDF File Handling Multiple Unspecified Input Validation... |
| 54472 | Xpdf JBIG2 Decoder PDF File Handling Multiple Unspecified Input Validation Fl... |
| 54471 | CUPS JBIG2 Decoder PDF File Handling Multiple Unspecified Input Validation Fl... |
| 54470 | Poppler JBIG2 MMR Decoder Crafted PDF Handling Arbitrary Code Execution |
| 54469 | Xpdf JBIG2 MMR Decoder Crafted PDF Handling Arbitrary Code Execution |
| 54468 | CUPS JBIG2 MMR Decoder Crafted PDF Handling Arbitrary Code Execution |
| 54467 | Poppler JBIG2 MMR Decoder Crafted PDF File Handling Infinite Loop DoS |
| 54466 | CUPS JBIG2 MMR Decoder Crafted PDF File Handling Infinite Loop DoS |
| 54465 | Xpdf JBIG2 MMR Decoder Crafted PDF File Handling Infinite Loop DoS |

RHSA-2009:0431
(High)
(Medium)






