[UCI-Linux] [SECURITY] Fedora Core 4 Update: xpdf-3.01-0.FC4.5

Mike Iglesias iglesias at draco.acs.uci.edu
Sat Dec 17 08:26:17 PST 2005

From: "Than Ngo" <than at redhat.com>
To: fedora-announce-list at redhat.com
Date: Sat, 17 Dec 2005 02:01:37 -0500
Subject: [SECURITY] Fedora Core 4 Update: xpdf-3.01-0.FC4.5

Fedora Update Notification

Product     : Fedora Core 4
Name        : xpdf
Version     : 3.01                      
Release     : 0.FC4.5                  
Summary     : A PDF file viewer for the X Window System.
Description :
Xpdf is an X Window System based viewer for Portable Document Format
(PDF) files. Xpdf is a small and efficient program which uses
standard X fonts.

Update Information:

Several flaws were discovered in Xpdf. An attacker could
construct a carefully crafted PDF file that could cause xpdf
to crash or possibly execute arbitrary code when opened. The
Common Vulnerabilities and Exposures project assigned the
name CAN-2005-3193 to these issues.

Users of xpdf should upgrade to this updated package, which
contains a patch to resolve these issues.
* Wed Dec 14 2005 Kristian Høgsberg <krh at redhat.com> 1:3.01-0.FC4.5
- Bump release.
- Update sources file and drop t1lib support entirely.

* Wed Dec 14 2005 Kristian Høgsberg <krh at redhat.com> 1:3.01-0.FC4.4
- Add xpdf-3.01-CVE-2005-3191.patch to fix security bug #173888 and
  merge embargo branch back to FC-4

This update can be downloaded from:

8eb2b8dde353ab48730c89972991a2fc  SRPMS/xpdf-3.01-0.FC4.5.src.rpm
012186b96a434e36c7b04bdda865e8e5  ppc/xpdf-3.01-0.FC4.5.ppc.rpm
c43973989dae59251a1f6f2ea1c3596e  ppc/debug/xpdf-debuginfo-3.01-0.FC4.5.ppc.rpm
9e70f7a2df42688105546aca78da6faf  x86_64/xpdf-3.01-0.FC4.5.x86_64.rpm
7eaf3e7bda92dd7ab210de5f103a12cf  x86_64/debug/xpdf-debuginfo-3.01-0.FC4.5.x86_64.rpm
4ec1702606e69f0aea8265951e6bd83d  i386/xpdf-3.01-0.FC4.5.i386.rpm
effbf4cfdbb8284d4963a1d9db0270a3  i386/debug/xpdf-debuginfo-3.01-0.FC4.5.i386.rpm

This update can also be installed with the Update Agent; you can
launch the Update Agent with the 'up2date' command.  

fedora-announce-list mailing list
fedora-announce-list at redhat.com

More information about the UCI-Linux mailing list