Referenced CVEs:
CVE-2009-0755, CVE-2009-3603, CVE-2009-3604, CVE-2009-3605, CVE-2009-3607, CVE-2009-3608, CVE-2009-3609
Description:
===========================================================Ubuntu Security Notice USN-850-1 October 21, 2009poppler vulnerabilitiesCVE-2009-0755, CVE-2009-3603, CVE-2009-3604, CVE-2009-3605,CVE-2009-3607, CVE-2009-3608, CVE-2009-3609===========================================================A security issue affects the following Ubuntu releases:Ubuntu 6.06 LTSUbuntu 8.04 LTSUbuntu 8.10Ubuntu 9.04This advisory also applies to the corresponding versions ofKubuntu, Edubuntu, and Xubuntu.The problem can be corrected by upgrading your system to thefollowing package versions:Ubuntu 6.06 LTS: libpoppler1 0.5.1-0ubuntu7.6 libpoppler1-glib 0.5.1-0ubuntu7.6Ubuntu 8.04 LTS: libpoppler-glib2 0.6.4-1ubuntu3.3 libpoppler2 0.6.4-1ubuntu3.3Ubuntu 8.10: libpoppler-glib3 0.8.7-1ubuntu0.4 libpoppler3 0.8.7-1ubuntu0.4Ubuntu 9.04: libpoppler-glib4 0.10.5-1ubuntu2.4 libpoppler4 0.10.5-1ubuntu2.4In general, a standard system upgrade is sufficient to effect thenecessary changes.Details follow:It was discovered that poppler contained multiple security issues whenparsing malformed PDF documents. If a user or automated system were trickedinto opening a crafted PDF file, an attacker could cause a denial ofservice or execute arbitrary code with privileges of the user invoking theprogram.
More...