Oracle Linux 5 : poppler (ELSA-2008-0239)
Medium Nessus Plugin ID 67687
SynopsisThe remote Oracle Linux host is missing one or more security updates.
DescriptionFrom Red Hat Security Advisory 2008:0239 :
Updated poppler packages that fix a security issue are now available for Red Hat Enterprise Linux 5.
This update has been rated as having important security impact by the Red Hat Security Response Team.
Poppler is a PDF rendering library, used by applications such as Evince.
Kees Cook discovered a flaw in the way poppler displayed malformed fonts embedded in PDF files. An attacker could create a malicious PDF file that would cause applications that use poppler -- such as Evince
-- to crash, or, potentially, execute arbitrary code when opened.
Users are advised to upgrade to these updated packages, which contain backported patches to resolve this issue.
SolutionUpdate the affected poppler packages.