Bug#443906: CVE-2007-5049 stack based buffer overflow

2007-09-27 Thread Nico Golde
Hi, I intend to NMU this bug since xpdf is the last package which is vulnerable to this poppler bug. The attached patch fixes this issue. It will be also archived on: http://people.debian.org/~nion/nmu-diff/xpdf-3.02-1.1_3.02-1.2.patch Kind regards Nico -- Nico Golde - http://ngolde.de - [EMAI

Bug#443906: CVE-2007-5049 stack based buffer overflow

2007-09-24 Thread Nico Golde
Package: xpdf Severity: grave Tags: security Hi, the following CVE (Common Vulnerabilities & Exposures) id was published for xpdf. CVE-2007-5049[0]: | Stack-based buffer overflow in the StreamPredictor::getNextLine | function in xpdf, as used in (1) poppler before 0.5.91, (2) gpdf, (3) | kpdf, (4