[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
RHN Errata Alert: Important: poppler security and bug fix update
- Subject: RHN Errata Alert: Important: poppler security and bug fix update
- From: Red Hat Network Alert <dev-null@rhn.redhat.com>
- Date: Mon, 19 Oct 2009 08:46:11 -0400
Red Hat Network has determined that the following advisory is applicable to
one or more of the systems you have registered:
Complete information about this errata can be found at the following location:
https://rhn.redhat.com/rhn/errata/details/Details.do?eid=9265
Security Advisory - RHSA-2009:1504-1
------------------------------------------------------------------------------
Summary:
Important: poppler security and bug fix update
Updated poppler packages that fix multiple security issues and a bug are
now available for Red Hat Enterprise Linux 5.
This update has been rated as having important security impact by the Red
Hat Security Response Team.
Description:
Poppler is a Portable Document Format (PDF) rendering library, used by
applications such as Evince.
Multiple integer overflow flaws were found in poppler. An attacker could
create a malicious PDF file that would cause applications that use poppler
(such as Evince) to crash or, potentially, execute arbitrary code when
opened. (CVE-2009-3603, CVE-2009-3608, CVE-2009-3609)
Red Hat would like to thank Chris Rohlf for reporting the CVE-2009-3608
issue.
This update also corrects a regression introduced in the previous poppler
security update, RHSA-2009:0480, that prevented poppler from rendering
certain PDF documents correctly. (BZ#528147)
Users are advised to upgrade to these updated packages, which contain
backported patches to resolve these issues.
References:
http://www.redhat.com/security/updates/classification/#important
------------------------------------------------------------------------------
-------------
Taking Action
-------------
You may address the issues outlined in this advisory in two ways:
- select your server name by clicking on its name from the list
available at the following location, and then schedule an
errata update for it:
https://rhn.redhat.com/rhn/systems/SystemList.do
- run the Update Agent on each affected server.
---------------------------------
Changing Notification Preferences
---------------------------------
To enable/disable your Errata Alert preferences globally please log in to RHN
and navigate from "Your RHN" / "Your Account" to the "Preferences" tab.
URL: https://rhn.redhat.com/rhn/account/UserPreferences.do
You can also enable/disable notification on a per system basis by selecting an
individual system from the "Systems List". From the individual system view
click the "Details" tab.
---------------------
Affected Systems List
---------------------
This Errata Advisory may apply to the systems listed below. If you know that
this errata does not apply to a system listed, it might be possible that the
package profile for that server is out of date. In that case you should refresh
the system's package profile by running *one* of the following commands as root
on that system:
* 'up2date -p' (on Enterprise Linux systems prior to RHEL5)
* 'rhn-profile-sync' (on Enterprise Linux 5 or later)
There is 1 affected system registered in 'Your RHN' (only systems for
which you have explicitly enabled Errata Alerts are shown).
Release Arch Profile Name
-------- -------- ------------
The Red Hat Network Team
This message is being sent by Red Hat Network Alert to:
RHN user login: uci-oir
If you lost your RHN password, you can use the information above to
retrieve it by email from the following address:
htts://www.redhat.com/wapps/sso/rhn/lostPassword.html
To cancel these notices, go to:
https://rhn.redhat.com/rhn/account/UserPreferences.do