CentOS 5 : poppler (CESA-2009:1504)
High Nessus Plugin ID 43804
SynopsisThe remote CentOS host is missing one or more security updates.
DescriptionUpdated poppler packages that fix multiple security issues and a bug are now available for Red Hat Enterprise Linux 5.
This update has been rated as having important security impact by the Red Hat Security Response Team.
Poppler is a Portable Document Format (PDF) rendering library, used by applications such as Evince.
Multiple integer overflow flaws were found in poppler. An attacker could create a malicious PDF file that would cause applications that use poppler (such as Evince) to crash or, potentially, execute arbitrary code when opened. (CVE-2009-3603, CVE-2009-3608, CVE-2009-3609)
Red Hat would like to thank Chris Rohlf for reporting the CVE-2009-3608 issue.
This update also corrects a regression introduced in the previous poppler security update, RHSA-2009:0480, that prevented poppler from rendering certain PDF documents correctly. (BZ#528147)
Users are advised to upgrade to these updated packages, which contain backported patches to resolve these issues.
SolutionUpdate the affected poppler packages.