Re: Please hint poppler 0.4.5-5.1

2007-01-22 Thread Frank Küster
Steve Langasek debian.org> writes: > On Mon, Jan 22, 2007 at 07:46:45AM +, Neil McGovern wrote: > > For info, we do have this tracked as fixed in 0.4.5-5.1 but: > > > Notes: > > hardly a security issue; if someone sends someone a crafted PDF file > > triggering such an endless loop the u

Re: Please hint poppler 0.4.5-5.1

2007-01-22 Thread Steve Langasek
On Mon, Jan 22, 2007 at 08:06:29AM +0100, Ondřej Surý wrote: >* SECURITY UPDATE: Denial of Service. >* New patch, 108_CVE-2007-0104; limits recursion depth of the parsing tree > to > 100 to avoid infinite loop with crafted documents; CVE-2007-0104; from > Ubuntu's 0.4.2-0ubuntu6.

Re: Please hint poppler 0.4.5-5.1

2007-01-21 Thread Neil McGovern
On Mon, Jan 22, 2007 at 08:06:29AM +0100, Ondřej Surý wrote: >* SECURITY UPDATE: Denial of Service. >* New patch, 108_CVE-2007-0104; limits recursion depth of the parsing tree > to > 100 to avoid infinite loop with crafted documents; CVE-2007-0104; from > Ubuntu's 0.4.2-0ubuntu6.

Please hint poppler 0.4.5-5.1

2007-01-21 Thread Ondřej Surý
* SECURITY UPDATE: Denial of Service. * New patch, 108_CVE-2007-0104; limits recursion depth of the parsing tree to 100 to avoid infinite loop with crafted documents; CVE-2007-0104; from Ubuntu's 0.4.2-0ubuntu6.8; originally taken from koffice security update; Thanks, -- Ondřej Su