Debian Security Advisory DSA 932-1 (xpdf)

Summary
The remote host is missing an update to xpdf announced via advisory DSA 932-1. infamous41md and Chris Evans discovered several heap based buffer overflows in xpdf, the Portable Document Format (PDF) suite, that can lead to a denial of service by crashing the application or possibly to the execution of arbitrary code. The same code is present in kpdf which is part of the kdegraphics package. The old stable distribution (woody) does not contain kpdf packages.
Solution
For the stable distribution (sarge) these problems have been fixed in version 3.3.2-2sarge3. For the unstable distribution (sid) these problems have been fixed in version 3.5.0-3. We recommend that you upgrade your kpdf package. https://secure1.securityspace.com/smysecure/catid.html?in=DSA%20932-1