漏洞信息详情
XPDF多个未明漏洞
- CNNVD编号:CNNVD-200603-272
- 危害等级: 高危
- CVE编号:
CVE-2006-1244
- 漏洞类型:
资料不足
- 发布时间:
2006-03-15
- 威胁类型:
远程
- 更新时间:
2006-08-28
- 厂 商:
gnome - 漏洞来源:
Discovered by Dere… -
漏洞简介
在xpdf 3.00后的某个版本中存在不明漏洞,当使用在包括(a) pdfkit.framework,(b) gpdf,(c) pdftohtml,和(d) libextractor的不同产品中时,会产生不明影响和用户协助式攻击向量,可能在(1) gmem.c,(2) SplashXPathScanner.cc,(3) JBIG2Stream.cc,(4) JPXStream.cc,和/或(5) Stream.cc中会出现相关错误。
漏洞公告
目前厂商已经发布了升级补丁以修复这个安全问题,补丁下载链接:
libextractor libextractor 0.4.2
Debian extract_0.4.2-2sarge3_alpha.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/libe/libextractor/extract
_0.4.2-2sarge3_alpha.deb
Debian extract_0.4.2-2sarge3_amd64.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/libe/libextractor/extract
_0.4.2-2sarge3_amd64.deb
Debian extract_0.4.2-2sarge3_arm.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/libe/libextractor/extract
_0.4.2-2sarge3_arm.deb
Debian extract_0.4.2-2sarge3_hppa.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/libe/libextractor/extract
_0.4.2-2sarge3_hppa.deb
Debian extract_0.4.2-2sarge3_i386.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/libe/libextractor/extract
_0.4.2-2sarge3_i386.deb
Debian extract_0.4.2-2sarge3_ia64.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/libe/libextractor/extract
_0.4.2-2sarge3_ia64.deb
Debian extract_0.4.2-2sarge3_m68k.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/libe/libextractor/extract
_0.4.2-2sarge3_m68k.deb
Debian extract_0.4.2-2sarge3_mips.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/libe/libextractor/extract
_0.4.2-2sarge3_mips.deb
Debian extract_0.4.2-2sarge3_mipsel.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/libe/libextractor/extract
_0.4.2-2sarge3_mipsel.deb
Debian extract_0.4.2-2sarge3_powerpc.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/libe/libextractor/extract
_0.4.2-2sarge3_powerpc.deb
Debian extract_0.4.2-2sarge3_s390.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/libe/libextractor/extract
_0.4.2-2sarge3_s390.deb
Debian extract_0.4.2-2sarge3_sparc.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/libe/libextractor/extract
_0.4.2-2sarge3_sparc.deb
Debian libextractor1-dev_0.4.2-2sarge3_alpha.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/libe/libextractor/libextr
actor1-dev_0.4.2-2sarge3_alpha.deb
Debian libextractor1-dev_0.4.2-2sarge3_amd64.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/libe/libextractor/libextr
actor1-dev_0.4.2-2sarge3_amd64.deb
Debian libextractor1-dev_0.4.2-2sarge3_arm.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/libe/libextractor/libextr
actor1-dev_0.4.2-2sarge3_arm.deb
Debian libextractor1-dev_0.4.2-2sarge3_hppa.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/libe/libextractor/libextr
actor1-dev_0.4.2-2sarge3_hppa.deb
Debian libextractor1-dev_0.4.2-2sarge3_i386.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/libe/libextractor/libextr
actor1-dev_0.4.2-2sarge3_i386.deb
Debian libextractor1-dev_0.4.2-2sarge3_ia64.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/libe/libextractor/libextr
actor1-dev_0.4.2-2sarge3_ia64.deb
Debian libextractor1-dev_0.4.2-2sarge3_m68k.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/libe/libextractor/libextr
actor1-dev_0.4.2-2sarge3_m68k.deb
Debian libextractor1-dev_0.4.2-2sarge3_mips.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/libe/libextractor/libextr
actor1-dev_0.4.2-2sarge3_mips.deb
Debian libextractor1-dev_0.4.2-2sarge3_mipsel.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/libe/libextractor/libextr
actor1-dev_0.4.2-2sarge3_mipsel.deb
Debian libextractor1-dev_0.4.2-2sarge3_powerpc.deb
Debian GNU/L
参考网址
来源: DEBIAN
名称: DSA-998
链接:http://www.debian.org/security/2006/dsa-998
来源: DEBIAN
名称: DSA-984
链接:http://www.debian.org/security/2006/dsa-984
来源: DEBIAN
名称: DSA-983
链接:http://www.debian.org/security/2006/dsa-983
来源: DEBIAN
名称: DSA-982
链接:http://www.debian.org/security/2006/dsa-982
来源: DEBIAN
名称: DSA-979
链接:http://www.debian.org/security/2006/dsa-979
来源: DEBIAN
名称: DSA-1019
链接:http://www.debian.org/security/2006/dsa-1019
来源: MISC
链接:http://security.debian.org/pool/updates/main/p/pdfkit.framework/pdfkit.framework_0.8-2sarge3.diff.gz
来源: SECUNIA
名称: 19644
链接:http://secunia.com/advisories/19644
来源: SECUNIA
名称: 19364
链接:http://secunia.com/advisories/19364
来源: SECUNIA
名称: 19164
链接:http://secunia.com/advisories/19164
来源: SECUNIA
名称: 19091
链接:http://secunia.com/advisories/19091
来源: SECUNIA
名称: 19065
链接:http://secunia.com/advisories/19065
来源: SECUNIA
名称: 19021
链接:http://secunia.com/advisories/19021
来源: SECUNIA
名称: 18948
链接:http://secunia.com/advisories/18948
来源: UBUNTU
名称: USN-270-1
链接:http://www.ubuntulinux.org/support/documentation/usn/usn-270-1
来源: BID
名称: 16748
链接:http://www.securityfocus.com/bid/16748
来源: OSVDB
名称: 23834