Package name pdftohtml
Date August 13th, 2007
Advisory ID MDKSA-2007:160
Affected versions 2007.0, 2007.1

Problem Description

Maurycy Prodeus found an integer overflow vulnerability in the way
various PDF viewers processed PDF files. An attacker could create a
malicious PDF file that could cause pdftohtml to crash and possibly
execute arbitrary code open a user opening the file.

This update provides packages which are patched to prevent these
issues.

Updated Packages

Mandriva Linux 2007

 4592a1f7115b10ad63444f4573a30365  2007.0/i586/pdftohtml-0.36-5.2mdv2007.0.i586.rpm 
 ed0f9331d0f7042c9ef0df41d28c1e69  2007.0/SRPMS/pdftohtml-0.36-5.2mdv2007.0.src.rpm

Mandriva Linux 2007/X86_64

 686d03f528d949957ff5884bb505d762  2007.0/x86_64/pdftohtml-0.36-5.2mdv2007.0.x86_64.rpm 
 ed0f9331d0f7042c9ef0df41d28c1e69  2007.0/SRPMS/pdftohtml-0.36-5.2mdv2007.0.src.rpm

Mandriva Linux 2007.1

 66426070761def5ae0ee9f6f1b174a46  2007.1/i586/pdftohtml-0.39-1.1mdv2007.1.i586.rpm 
 17a547b0f2d2fecc5800083143dc730f  2007.1/SRPMS/pdftohtml-0.39-1.1mdv2007.1.src.rpm

Mandriva Linux 2007.1/X86_64

 2d572fa290a490bbcaff73898c95a2af  2007.1/x86_64/pdftohtml-0.39-1.1mdv2007.1.x86_64.rpm 
 17a547b0f2d2fecc5800083143dc730f  2007.1/SRPMS/pdftohtml-0.39-1.1mdv2007.1.src.rpm

References

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3387

Upgrade

To upgrade automatically, use MandrivaUpdate.


Verification

Please verify the update prior to upgrading to ensure the integrity of the downloaded package. You can do this with the command :

		rpm --checksig package.rpm
		

You can get the GPG public key of the Mandriva Security Team to verify the GPG signature of each RPM.

If you use MandrivaUpdate, the verification of md5 checksum and GPG signature is performed automatically for you.