GLSA: xpdf

From: Daniel Ahlberg (alizat_private)
Date: Thu Jan 02 2003 - 02:17:50 PST

  • Next message: Daniel Ahlberg: "GLSA: leafnode"

    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA1
    
    - - --------------------------------------------------------------------
    GENTOO LINUX SECURITY ANNOUNCEMENT 200301-1
    - - --------------------------------------------------------------------
    
    PACKAGE : xpdf
    SUMMARY : integer overflow
    DATE    : 2003-01-02 10:01 UTC
    EXPLOIT : local and remote
    
    - - --------------------------------------------------------------------
    
    - From iDEFENSE advisory:
    
    "The pdftops filter in the Xpdf and CUPS packages contains an integer 
    overflow that can be exploited to gain the privileges of the target user 
    or in some cases the increased privileges of the 'lp' user if installed 
    setuid. There are multiple ways of exploiting this vulnerability."
    
    Read the full advisory at
    http://www.idefense.com/advisory/12.23.02.txt
    
    SOLUTION
    
    It is recommended that all Gentoo Linux users who are running
    app-text/xpdf-1.01-r1 or earlier update their systems as 
    follows:
    
    emerge rsync
    emerge xpdf
    emerge clean
    
    - - --------------------------------------------------------------------
    alizat_private - GnuPG key is available at www.gentoo.org/~aliz
    - - --------------------------------------------------------------------
    -----BEGIN PGP SIGNATURE-----
    Version: GnuPG v1.2.1 (GNU/Linux)
    
    iD8DBQE+FBHDfT7nyhUpoZMRArLLAJwJ/iqCxaKfUqvTSC6jXFTlwhA25ACfXosJ
    CM9T0JTkOYDhJIVj7xgZ/5A=
    =qDHF
    -----END PGP SIGNATURE-----
    



    This archive was generated by hypermail 2b30 : Thu Jan 02 2003 - 18:51:58 PST