GLSA: tetex

From: Daniel Ahlberg (alizat_private)
Date: Fri Oct 18 2002 - 14:56:38 PDT

  • Next message: Dave Aitel: "[Full-Disclosure] [Immunity, Inc.]Vulnerability: RPC Service DoS (port 135/tcp) on Windows 2000 SP3"

    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA1
    
    - - --------------------------------------------------------------------
    GENTOO LINUX SECURITY ANNOUNCEMENT 200210-004
    - - --------------------------------------------------------------------
    
    PACKAGE : tetex
    SUMMARY : Command execution vulnerability in dvips
    EXPLOIT : local & remote
    DATE    : 2002-10-18 22:00 UTC
    
    - - --------------------------------------------------------------------
    
    Olaf Kirch of SuSE has discovered a vulnerability in dvips that
    allowed remote users with printing access to execute command as the 
    lp user by sending carefully crafted printjobs. 
    
    SOLUTION
    
    It is recommended that all Gentoo Linux users who are running
    app-text/tetex-1.0.7-r10 and earlier update their systems
    as follows:
    
    emerge rsync
    emerge tetex
    emerge clean
    
    - - --------------------------------------------------------------------
    alizat_private - GnuPG key is available at www.gentoo.org/~aliz
    - - --------------------------------------------------------------------
    -----BEGIN PGP SIGNATURE-----
    Version: GnuPG v1.2.0 (GNU/Linux)
    
    iD8DBQE9sIOVfT7nyhUpoZMRAto7AJ0RU7DDa3SpqQvBoeUKImMs4mEisgCggQNe
    4qSNCwk2T6bcxePUOmHbDy4=
    =eIne
    -----END PGP SIGNATURE-----
    



    This archive was generated by hypermail 2b30 : Fri Oct 18 2002 - 15:14:23 PDT