An updated xpdf package that fixes several security issues is now available.
This update has been rated as having important security impact by the Red
Hat Security Response Team.
[Updated 20 Dec 2005]
The initial fix for these issues was incomplete. The packages have been
updated with a more complete fix.
The xpdf package is an X Window System-based viewer for Portable Document
Format (PDF) files.
Several flaws were discovered in Xpdf. An attacker could construct a
carefully crafted PDF file that could cause Xpdf to crash or possibly
execute arbitrary code when opened. The Common Vulnerabilities and
Exposures project assigned the names CVE-2005-3191, CVE-2005-3192, and
CVE-2005-3193 to these issues.
Users of Xpdf should upgrade to this updated package, which contains a
backported patch to resolve these issues.
CentOS would like to thank Derek B. Noonburg for reporting this issue and
providing a patch.