Your message dated Fri, 10 Aug 2007 04:17:03 +0000
with message-id <[EMAIL PROTECTED]>
and subject line Bug#435460: fixed in poppler 0.5.4-6.1
has caused the attached Bug report to be marked as done.
This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.
(NB: If you are a system administrator and have no idea what I am
talking about this indicates a serious mail system misconfiguration
somewhere. Please contact me immediately.)
Debian bug tracking system administrator
(administrator, Debian Bugs database)
--- Begin Message ---
Package: libpoppler1
Version: 0.5.4-6
Severity: grave
Tags: security
Justification: user security hole
A vulnerability has been found in libpoppler and related
packages. From CVE-2007-3387:
"Integer overflow in the StreamPredictor::StreamPredictor function in gpdf
before
2.8.2, as used in (1) poppler, (2) xpdf, (3) kpdf, (4) kdegraphics, (5) CUPS,
and other products, might allow remote attackers to execute arbitrary code via a
crafted PDF file."
Please mention the CVE id in the changelog.
--- End Message ---
--- Begin Message ---
Source: poppler
Source-Version: 0.5.4-6.1
We believe that the bug you reported is fixed in the latest version of
poppler, which is due to be installed in the Debian FTP archive:
libpoppler-dev_0.5.4-6.1_i386.deb
to pool/main/p/poppler/libpoppler-dev_0.5.4-6.1_i386.deb
libpoppler-glib-dev_0.5.4-6.1_i386.deb
to pool/main/p/poppler/libpoppler-glib-dev_0.5.4-6.1_i386.deb
libpoppler-glib1_0.5.4-6.1_i386.deb
to pool/main/p/poppler/libpoppler-glib1_0.5.4-6.1_i386.deb
libpoppler-qt-dev_0.5.4-6.1_i386.deb
to pool/main/p/poppler/libpoppler-qt-dev_0.5.4-6.1_i386.deb
libpoppler-qt1_0.5.4-6.1_i386.deb
to pool/main/p/poppler/libpoppler-qt1_0.5.4-6.1_i386.deb
libpoppler-qt4-1_0.5.4-6.1_i386.deb
to pool/main/p/poppler/libpoppler-qt4-1_0.5.4-6.1_i386.deb
libpoppler-qt4-dev_0.5.4-6.1_i386.deb
to pool/main/p/poppler/libpoppler-qt4-dev_0.5.4-6.1_i386.deb
libpoppler1_0.5.4-6.1_i386.deb
to pool/main/p/poppler/libpoppler1_0.5.4-6.1_i386.deb
poppler-utils_0.5.4-6.1_i386.deb
to pool/main/p/poppler/poppler-utils_0.5.4-6.1_i386.deb
poppler_0.5.4-6.1.diff.gz
to pool/main/p/poppler/poppler_0.5.4-6.1.diff.gz
poppler_0.5.4-6.1.dsc
to pool/main/p/poppler/poppler_0.5.4-6.1.dsc
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to [EMAIL PROTECTED],
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Steffen Joeris <[EMAIL PROTECTED]> (supplier of updated poppler package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [EMAIL PROTECTED])
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
Format: 1.7
Date: Sun, 05 Aug 2007 11:08:24 +0000
Source: poppler
Binary: libpoppler-glib-dev poppler-utils libpoppler-qt4-dev libpoppler-qt1
libpoppler1 libpoppler-glib1 libpoppler-qt4-1 libpoppler-dev libpoppler-qt-dev
Architecture: source i386
Version: 0.5.4-6.1
Distribution: unstable
Urgency: high
Maintainer: OndÅej Surý <[EMAIL PROTECTED]>
Changed-By: Steffen Joeris <[EMAIL PROTECTED]>
Description:
libpoppler-dev - PDF rendering library -- development files
libpoppler-glib-dev - PDF rendering library -- development files (GLib
interface)
libpoppler-glib1 - PDF rendering library (GLib-based shared library)
libpoppler-qt-dev - PDF rendering library -- development files (Qt 3 interface)
libpoppler-qt1 - PDF rendering library (Qt 3 based shared library)
libpoppler-qt4-1 - PDF rendering library (Qt 4 based shared library)
libpoppler-qt4-dev - PDF rendering library -- development files (Qt 4
interface)
libpoppler1 - PDF rendering library
poppler-utils - PDF utilitites (based on libpoppler)
Closes: 435460
Changes:
poppler (0.5.4-6.1) unstable; urgency=high
.
* Non-maintainer upload
* Include upstream patch to fix integer overflow in the
StreamPredictor::StreamPredictor function
(Closes: #435460) Fixes: CVE-2007-3387
Files:
55c8573e83e17a24de3561bf515f7331 1086 devel optional poppler_0.5.4-6.1.dsc
33447ce4205fd491884376fca24410ba 9930 devel optional poppler_0.5.4-6.1.diff.gz
ed2625dff323c4a8383f9733fdaf560c 578854 libs optional
libpoppler1_0.5.4-6.1_i386.deb
3702de8f758747eebda2a23c96d80c05 767476 libdevel optional
libpoppler-dev_0.5.4-6.1_i386.deb
dfd53f60d7a15edd72b577505ed58fb0 72194 libs optional
libpoppler-glib1_0.5.4-6.1_i386.deb
503d1eedc5c55cefa00e979ea42dd6cd 100822 libdevel optional
libpoppler-glib-dev_0.5.4-6.1_i386.deb
dbc4eee1926ffd8df621797d88303d85 60288 libs optional
libpoppler-qt1_0.5.4-6.1_i386.deb
2ab9d3ab0f7f5f69bf76d50eb8fbc0b5 64070 libdevel optional
libpoppler-qt-dev_0.5.4-6.1_i386.deb
4e9f14a86d3216e47c9fd0e9a4ccc891 152192 libs optional
libpoppler-qt4-1_0.5.4-6.1_i386.deb
304ba69396149635c639b54dc3e58776 174050 libdevel optional
libpoppler-qt4-dev_0.5.4-6.1_i386.deb
97fbbdec9212685f2c5156a79b4c5180 103306 utils optional
poppler-utils_0.5.4-6.1_i386.deb
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.6 (GNU/Linux)
iD8DBQFGu+Mo62zWxYk/rQcRAuaVAKClhX2BeIsMQWRVlnH/I4vHiA0fwgCbBTTG
GgHQgdAWtue4Anrgv5vzSYs=
=NTzd
-----END PGP SIGNATURE-----
--- End Message ---