USN-410-2: teTeX vulnerability

Ubuntu Security Notice USN-410-2

25th January, 2007

tetex-bin vulnerability

A security issue affects these releases of Ubuntu and its derivatives:

  • Ubuntu 5.10


USN-410-1 fixed vulnerabilities in the poppler PDF loader library. This
update provides the corresponding updates for a copy of this code in
tetex-bin in Ubuntu 5.10. Versions of tetex-bin after Ubuntu 5.10 use
poppler directly and do not need a separate update.

Original advisory details:

The poppler PDF loader library did not limit the recursion depth of
the page model tree. By tricking a user into opening a specially
crafter PDF file, this could be exploited to trigger an infinite loop
and eventually crash an application that uses this library.

Update instructions

The problem can be corrected by updating your system to the following package version:

Ubuntu 5.10:
tetex-bin 2.0.2-30ubuntu3.6

To update your system, please follow these instructions:

In general, a standard system upgrade is sufficient to effect the
necessary changes.