|
KDE kpdf Xpdf Buffer Overflow Vulnerabilities
|
|
Secunia Advisory:
|
SA17920
|
|
|
Release Date:
|
2005-12-07
|
|
Last Update:
|
2006-03-10
|
|
Popularity:
|
9,318 views
|
|
|
Critical:
|
 Moderately critical
|
|
Impact:
|
DoS System access
|
|
Where:
|
From remote
|
|
Solution Status:
|
Vendor Patch
|
|
| Software: | KDE 3.x
|
|
|
Subscribe:
|
Instant alerts on relevant vulnerabilities
|
|
| CVE reference: | CVE-2005-3191 CVE-2005-3192 CVE-2005-3193 CVE-2005-3624 CVE-2005-3625 CVE-2005-3626 CVE-2005-3627 CVE-2006-0746
|
|
Description: Some vulnerabilities have been reported in KDE kpdf, which can be exploited by malicious people to cause a DoS (Denial of Service) and potentially to compromise a user's system.
The vulnerabilities are caused due to the use of a vulnerable version of Xpdf.
For more information:
SA17897
SA18303
The vulnerabilities have been reported in kpdf included with KDE versions 3.2.0 through 3.5.0.
Solution: Apply patches.
KDE 3.5.0:
ftp://ftp.kde.org/pub/kde/security_pa...-3.5.0-kdegraphics-CAN-2005-3193.diff
17ea076e986be5e26a4feea3cd264f7e
KDE 3.4.3:
ftp://ftp.kde.org/pub/kde/security_pa...-3.4.3-kdegraphics-CAN-2005-3193.diff
e8dde74416769d4589dcca25072aea3e
KDE 3.3.2:
ftp://ftp.kde.org/pub/kde/security_pa...-3.3.2-kdegraphics-CVE-2006-0746.diff
ea346b89a3b39915abbfd56841b9df23
KDE 3.2.3:
ftp://ftp.kde.org/pub/kde/security_pa...-3.2.3-kdegraphics-CAN-2005-3193.diff
51ae90242b7e65ba34c704b38c91cfbe
Provided and/or discovered by: The vendor credits Marcelo Ricardo Leitner for reporting the incomplete patch.
Changelog: 2005-12-08: Vendor released patches. Updated "Solution Status", "Description", "Solution", and "Original Advisory " sections.
2006-01-04: Vendor released new patches. The previous patch is reportedly incomplete.
2006-01-05: Updated "Description" and "Other References" sections.
2006-01-06: Updated "Impact" and "Description" sections.
2006-03-08: Updated "Solution Status", "Solution" and "Original Advisory" sections.
2006-03-10: Vendor issues new patch for KDE 3.3.2. Previous patch did not completely fix the vulnerability in version 3.3.2.
Original Advisory: KDE:
http://www.kde.org/info/security/advisory-20051207-1.txt
http://www.kde.org/info/security/advisory-20051207-2.txt
http://www.kde.org/info/security/advisory-20060310-1.txt
Red Hat Bugzilla:
https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=184308
Other References: SA17897:
http://secunia.com/advisories/17897/
SA18303:
http://secunia.com/advisories/18303/
|
|
|
Track this Secunia Advisory
|
Customers of the Secunia Vulnerability Intelligence solutions will automatically receive updates when new information regarding this advisory is released.
Read more about our Vulnerability Intelligence solutions and what they can do for you and your company.
|
|
|
About this Secunia Advisory
|
Please note: The information that this Secunia Advisory is based on comes from a third party unless stated otherwise.
Secunia collects, validates, and verifies all vulnerability reports issued by security research groups, vendors, and others.
|