Multiple integer overflows in xpdf 2.0 and 3.0, and other packages that use
xpdf code such as CUPS, gpdf, and kdegraphics, allow remote attackers to
cause a denial of service (crash) and possibly execute arbitrary code. An
attacker could create a malicious PDF file that could possibly execute
arbitrary code as the "lp" user if the file was printed. The patch for
integer overflow vulnerabilities in Xpdf 2.0 and 3.0 (CVE-2004-0888) is
incomplete for 64-bit architectures on certain Linux distributions such as
Red Hat, which could leave Xpdf users exposed to the original
vulnerabilities.