[Bluewhite64 Linux Security] xpdf [BW64SA:200905011-02]

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1


[Bluewhite64 Linux Security] xpdf [BW64SA:200905011-02]

New xpdf packages are available for Bluewhite64 Linux 11.0, 12.0, 12.1,
12.2, and -current to fix security issues.

More details about the issues may be found in the Common
Vulnerabilities and Exposures (CVE) database:

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0146
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0147
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0165
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0166
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0799
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0800
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1179
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1180
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1181
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1182
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1183



Here are the details from the Bluewhite64 Linux 12.2 ChangeLog:
- ----------------------------------------------------------------
PATCHES/packages/xpdf-3.02pl3-x86_64-1.tgz: Upgraded to xpdf-3.02pl3.
This update fixes several overflows that may result in crashes or the
execution of arbitrary code as the xpdf user.
For more information, see:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0146
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0147
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0165
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0166
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0799
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0800
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1179
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1180
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1181
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1182
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1183
[*** Security fix ***]


Download the new packages from:
- --------------------------------
For Bluewhite64 Linux 11.0:
http://data.bluewhite64.com/bluewhite64-11.0/patches/packages/xpdf-3.02pl3-x86_64-1.tgz

For Bluewhite64 Linux 12.0:
http://data.bluewhite64.com/bluewhite64-12.0/patches/packages/xpdf-3.02pl3-x86_64-1.tgz

For Bluewhite64 Linux 12.1:
http://data.bluewhite64.com/bluewhite64-12.1/patches/packages/xpdf-3.02pl3-x86_64-1.tgz

For Bluewhite64 Linux 12.2:
http://data.bluewhite64.com/bluewhite64-12.2/patches/packages/xpdf-3.02pl3-x86_64-1.tgz

For Bluewhite64 Linux -current:
http://data.bluewhite64.com/bluewhite64-current/bluewhite64/xap/xpdf-3.02pl3-x86_64-1.txz

Also, please see the "Get Bluewhite64" section on http://www.bluewhite64.com for
additional mirror sites near you.


MD5 signatures:
- ----------------
Bluewhite64 11.0 package:
f9e61f56774bd8ef77a14585e0ffdd3e xpdf-3.02pl3-x86_64-1.tgz

Bluewhite64 12.0 package:
ac31b713c7d3babe18b21abef6224c3b xpdf-3.02pl3-x86_64-1.tgz

Bluewhite64 12.1 package:
69c2cd680e9753ce128af7b51206f06a xpdf-3.02pl3-x86_64-1.tgz

Bluewhite64 12.2 package:
7833a4139aef149a28aa889652e6181b xpdf-3.02pl3-x86_64-1.tgz

Bluewhite64 -current package:
cf58e733c17deeaca9772515717430b7 xpdf-3.02pl3-x86_64-1.txz


Installation instructions:
- ----------------------------
Upgrade the package as root:
# upgradepkg xpdf-3.02pl3-x86_64-1.tgz



- ---
Bluewhite64 Linux Security Team
http://bluewhite64.com/gpg-key

security©bluewhite64.com



- ------------------------------------------------------
To leave the bluewhite64-security mailing list:
Send a blank email to

bluewhite64-security-unsubscribe©bluewhite64.com

You will get a confirmation message back containing
instructions to complete the process.

Please do not reply to this email address.
- ------------------------------------------------------



-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.9 (GNU/Linux)

iEYEARECAAYFAkoIdP8ACgkQpTOsxuDdlY5BvACeJP0x1PCDAo43zR087/3ZULJp
VNEAniCWvaCSUvjTROFySS0fENBwbLpz
=VW0T
-----END PGP SIGNATURE-----