Bug#342337: xpdf: Security hole CAN-2005-3193

2005-12-07 Thread Jan Niehusmann
On Thu, Dec 08, 2005 at 12:12:09AM +1100, Hamish Moffatt wrote: > On Wed, Dec 07, 2005 at 02:00:55PM +0100, Jan Niehusmann wrote: > > Ok, so you noticed that my analysis was not completely correct - while > > the woody version indeed doesn't contain JPXStream.cc (and consequently, > > the JPX strea

Bug#342337: xpdf: Security hole CAN-2005-3193

2005-12-07 Thread Hamish Moffatt
On Wed, Dec 07, 2005 at 02:00:55PM +0100, Jan Niehusmann wrote: > On Wed, Dec 07, 2005 at 11:42:08PM +1100, Hamish Moffatt wrote: > > merge 342281 342337 > Oops - I'm sorry, I missed that report. That's ok, thanks for helping. > > The fixed version is an update to 3.01, not 3.00. > I know, but th

Bug#342337: xpdf: Security hole CAN-2005-3193

2005-12-07 Thread Jan Niehusmann
On Wed, Dec 07, 2005 at 11:42:08PM +1100, Hamish Moffatt wrote: > merge 342281 342337 Oops - I'm sorry, I missed that report. > The fixed version is an update to 3.01, not 3.00. I know, but the patch applies to 3.00 without much trouble. > #342281 is already fixed in unstable. sarge and woody f

Bug#342337: xpdf: Security hole CAN-2005-3193

2005-12-07 Thread Hamish Moffatt
merge 342281 342337 thanks On Wed, Dec 07, 2005 at 10:30:15AM +0100, Jan Niehusmann wrote: > Package: xpdf-reader > Version: 3.00-13 > Severity: grave > Tags: security patch > Justification: user security hole > > CAN-2005-3193 lists a security hole of xpdf. A fix is available at > http://www.fo

Bug#342337: xpdf: Security hole CAN-2005-3193

2005-12-07 Thread Jan Niehusmann
Package: xpdf-reader Version: 3.00-13 Severity: grave Tags: security patch Justification: user security hole CAN-2005-3193 lists a security hole of xpdf. A fix is available at http://www.foolabs.com/xpdf/download.html (the patch seems to be suitable for a security update - only overflow protectio