Hi!

Helmut Grohne schrieb:
> Package: xpdf-reader
> Version: 3.02-1.4

I have the very same version.

> Severity: grave
> Justification: security
> 
> $ wget http://www.adobe.com/products/postscript/pdfs/PLRM.pdf
> ...
> $ sha256sum PLRM.pdf
> 6b29e79e4ab64aaa61a3fb27a0f36838c01f2530362873ac316bdb493a1bab6b PLRM.pdf

The very same document...

> $ xpdf PLRM.pdf
> ... (scoll down a few pages)
> Segmentation fault (core dumped)

I scolled down by now to page 345.  I didn't crashed yet.


> I do not know whether this has a security impact[1], so I go the safe
> way and report this as a security issue. If it turns out to be harmless,
> please downgrade the severity.

I would suggest to downgrade it, until there is an approach to reproduce
this bug (don't think is security related, either.)


Best regards,
  Alexander

Attachment: signature.asc
Description: OpenPGP digital signature

Reply via email to