XPDF多个未明漏洞

漏洞信息详情

XPDF多个未明漏洞

漏洞简介

在xpdf 3.00后的某个版本中存在不明漏洞,当使用在包括(a) pdfkit.framework,(b) gpdf,(c) pdftohtml,和(d) libextractor的不同产品中时,会产生不明影响和用户协助式攻击向量,可能在(1) gmem.c,(2) SplashXPathScanner.cc,(3) JBIG2Stream.cc,(4) JPXStream.cc,和/或(5) Stream.cc中会出现相关错误。

漏洞公告

目前厂商已经发布了升级补丁以修复这个安全问题,补丁下载链接:

libextractor libextractor 0.4.2

Debian extract_0.4.2-2sarge3_alpha.deb

Debian GNU/Linux 3.1 alias sarge

http://security.debian.org/pool/updates/main/libe/libextractor/extract

_0.4.2-2sarge3_alpha.deb

Debian extract_0.4.2-2sarge3_amd64.deb

Debian GNU/Linux 3.1 alias sarge

http://security.debian.org/pool/updates/main/libe/libextractor/extract

_0.4.2-2sarge3_amd64.deb

Debian extract_0.4.2-2sarge3_arm.deb

Debian GNU/Linux 3.1 alias sarge

http://security.debian.org/pool/updates/main/libe/libextractor/extract

_0.4.2-2sarge3_arm.deb

Debian extract_0.4.2-2sarge3_hppa.deb

Debian GNU/Linux 3.1 alias sarge

http://security.debian.org/pool/updates/main/libe/libextractor/extract

_0.4.2-2sarge3_hppa.deb

Debian extract_0.4.2-2sarge3_i386.deb

Debian GNU/Linux 3.1 alias sarge

http://security.debian.org/pool/updates/main/libe/libextractor/extract

_0.4.2-2sarge3_i386.deb

Debian extract_0.4.2-2sarge3_ia64.deb

Debian GNU/Linux 3.1 alias sarge

http://security.debian.org/pool/updates/main/libe/libextractor/extract

_0.4.2-2sarge3_ia64.deb

Debian extract_0.4.2-2sarge3_m68k.deb

Debian GNU/Linux 3.1 alias sarge

http://security.debian.org/pool/updates/main/libe/libextractor/extract

_0.4.2-2sarge3_m68k.deb

Debian extract_0.4.2-2sarge3_mips.deb

Debian GNU/Linux 3.1 alias sarge

http://security.debian.org/pool/updates/main/libe/libextractor/extract

_0.4.2-2sarge3_mips.deb

Debian extract_0.4.2-2sarge3_mipsel.deb

Debian GNU/Linux 3.1 alias sarge

http://security.debian.org/pool/updates/main/libe/libextractor/extract

_0.4.2-2sarge3_mipsel.deb

Debian extract_0.4.2-2sarge3_powerpc.deb

Debian GNU/Linux 3.1 alias sarge

http://security.debian.org/pool/updates/main/libe/libextractor/extract

_0.4.2-2sarge3_powerpc.deb

Debian extract_0.4.2-2sarge3_s390.deb

Debian GNU/Linux 3.1 alias sarge

http://security.debian.org/pool/updates/main/libe/libextractor/extract

_0.4.2-2sarge3_s390.deb

Debian extract_0.4.2-2sarge3_sparc.deb

Debian GNU/Linux 3.1 alias sarge

http://security.debian.org/pool/updates/main/libe/libextractor/extract

_0.4.2-2sarge3_sparc.deb

Debian libextractor1-dev_0.4.2-2sarge3_alpha.deb

Debian GNU/Linux 3.1 alias sarge

http://security.debian.org/pool/updates/main/libe/libextractor/libextr

actor1-dev_0.4.2-2sarge3_alpha.deb

Debian libextractor1-dev_0.4.2-2sarge3_amd64.deb

Debian GNU/Linux 3.1 alias sarge

http://security.debian.org/pool/updates/main/libe/libextractor/libextr

actor1-dev_0.4.2-2sarge3_amd64.deb

Debian libextractor1-dev_0.4.2-2sarge3_arm.deb

Debian GNU/Linux 3.1 alias sarge

http://security.debian.org/pool/updates/main/libe/libextractor/libextr

actor1-dev_0.4.2-2sarge3_arm.deb

Debian libextractor1-dev_0.4.2-2sarge3_hppa.deb

Debian GNU/Linux 3.1 alias sarge

http://security.debian.org/pool/updates/main/libe/libextractor/libextr

actor1-dev_0.4.2-2sarge3_hppa.deb

Debian libextractor1-dev_0.4.2-2sarge3_i386.deb

Debian GNU/Linux 3.1 alias sarge

http://security.debian.org/pool/updates/main/libe/libextractor/libextr

actor1-dev_0.4.2-2sarge3_i386.deb

Debian libextractor1-dev_0.4.2-2sarge3_ia64.deb

Debian GNU/Linux 3.1 alias sarge

http://security.debian.org/pool/updates/main/libe/libextractor/libextr

actor1-dev_0.4.2-2sarge3_ia64.deb

Debian libextractor1-dev_0.4.2-2sarge3_m68k.deb

Debian GNU/Linux 3.1 alias sarge

http://security.debian.org/pool/updates/main/libe/libextractor/libextr

actor1-dev_0.4.2-2sarge3_m68k.deb

Debian libextractor1-dev_0.4.2-2sarge3_mips.deb

Debian GNU/Linux 3.1 alias sarge

http://security.debian.org/pool/updates/main/libe/libextractor/libextr

actor1-dev_0.4.2-2sarge3_mips.deb

Debian libextractor1-dev_0.4.2-2sarge3_mipsel.deb

Debian GNU/Linux 3.1 alias sarge

http://security.debian.org/pool/updates/main/libe/libextractor/libextr

actor1-dev_0.4.2-2sarge3_mipsel.deb

Debian libextractor1-dev_0.4.2-2sarge3_powerpc.deb

Debian GNU/L

参考网址

来源: DEBIAN

名称: DSA-998

链接:http://www.debian.org/security/2006/dsa-998

来源: DEBIAN

名称: DSA-984

链接:http://www.debian.org/security/2006/dsa-984

来源: DEBIAN

名称: DSA-983

链接:http://www.debian.org/security/2006/dsa-983

来源: DEBIAN

名称: DSA-982

链接:http://www.debian.org/security/2006/dsa-982

来源: DEBIAN

名称: DSA-979

链接:http://www.debian.org/security/2006/dsa-979

来源: DEBIAN

名称: DSA-1019

链接:http://www.debian.org/security/2006/dsa-1019

来源: MISC

链接:http://security.debian.org/pool/updates/main/p/pdfkit.framework/pdfkit.framework_0.8-2sarge3.diff.gz

来源: SECUNIA

名称: 19644

链接:http://secunia.com/advisories/19644

来源: SECUNIA

名称: 19364

链接:http://secunia.com/advisories/19364

来源: SECUNIA

名称: 19164

链接:http://secunia.com/advisories/19164

来源: SECUNIA

名称: 19091

链接:http://secunia.com/advisories/19091

来源: SECUNIA

名称: 19065

链接:http://secunia.com/advisories/19065

来源: SECUNIA

名称: 19021

链接:http://secunia.com/advisories/19021

来源: SECUNIA

名称: 18948

链接:http://secunia.com/advisories/18948

来源: UBUNTU

名称: USN-270-1

链接:http://www.ubuntulinux.org/support/documentation/usn/usn-270-1

来源: BID

名称: 16748

链接:http://www.securityfocus.com/bid/16748

来源: OSVDB

名称: 23834

链接:http://www.osvdb.org/23834

受影响实体

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享