|
Issues the date: 2008-07-07
Renewal date: 2008-07-08
Is affected the system:
Poppler Poppler <= 0.8.4
Description:
--------------------------------------------------------------------------------
BUGTRAQ ID: 30107
CVE(CAN) ID: CVE-2008-2950
Poppler is one kind analyzes the PDF form documents the library of subroutines.
Poppler PDF exaggeration storehouse Page kind of structure/release function existence memory management crack, if has satisfied in the special condition Page structure function the initialization pageWidgets object, but regardless of after whether initialization, can delete this object in the release procedure. The aggressor may use this crack through the special PDF file allocation random memory to cause to carry out the random order.
<* origin: Andrea Barisani
Link: http://marc.info/?l=oss-security&m=121543962317828&w=2
*>
Suggested:
--------------------------------------------------------------------------------
Manufacturer patch:
Poppler
-------
At present the manufacturer has not provided the patch or the promotion procedure, we suggested that uses this software's user momentarily to pay attention to the manufacturer the main page to gain the newest edition:
http://poppler.freedesktop.org/
|