Your submission was sent successfully! Close

USN-410-2: teTeX vulnerability

26 January 2007

teTeX vulnerability

Releases

Details

USN-410-1 fixed vulnerabilities in the poppler PDF loader library. This
update provides the corresponding updates for a copy of this code in
tetex-bin in Ubuntu 5.10. Versions of tetex-bin after Ubuntu 5.10 use
poppler directly and do not need a separate update.

Original advisory details:

The poppler PDF loader library did not limit the recursion depth of
the page model tree. By tricking a user into opening a specially
crafter PDF file, this could be exploited to trigger an infinite loop
and eventually crash an application that uses this library.

Update instructions

The problem can be corrected by updating your system to the following package versions:

Ubuntu 5.10
  • tetex-bin - 2.0.2-30ubuntu3.6

In general, a standard system upgrade is sufficient to effect the
necessary changes.

References

Related notices

  • USN-410-1: libpoppler1, kpdf, libpoppler0c2, kword