Ubuntu 4.10 : xpdf, tetex-bin vulnerabilities (USN-48-1)

The remote Ubuntu host is missing one or more security-related patches.

A potential buffer overflow has been found in the xpdf viewer. An
insufficient input validation could be exploited by an attacker
providing a specially crafted PDF file which, when processed by xpdf,
could result in abnormal program termination or the execution of
attacker supplied program code with the user's privileges.

The tetex-bin package contains the affected xpdf code to generate PDF
output and process included PDF files, thus is vulnerable as well.

Update the affected packages.

High / CVSS Base Score : 9.3

CVE ID: CVE-2004-1125