Gentoo Archives: gentoo-announce

From: Daniel Ahlberg <aliz@g.o>
To: gentoo-announce@g.o
Subject: GLSA: xpdf
Date: Fri, 03 Jan 2003 18:58:20
Message-Id: 20030102101647.2DF6E5764@mail2.tamperd.net
1 -----BEGIN PGP SIGNED MESSAGE-----
2 Hash: SHA1
3
4 - - --------------------------------------------------------------------
5 GENTOO LINUX SECURITY ANNOUNCEMENT 200301-1
6 - - --------------------------------------------------------------------
7
8 PACKAGE : xpdf
9 SUMMARY : integer overflow
10 DATE    : 2003-01-02 10:01 UTC
11 EXPLOIT : local and remote
12
13 - - --------------------------------------------------------------------
14
15 - From iDEFENSE advisory:
16
17 "The pdftops filter in the Xpdf and CUPS packages contains an integer
18 overflow that can be exploited to gain the privileges of the target user
19 or in some cases the increased privileges of the 'lp' user if installed
20 setuid. There are multiple ways of exploiting this vulnerability."
21
22 Read the full advisory at
23 http://www.idefense.com/advisory/12.23.02.txt
24
25 SOLUTION
26
27 It is recommended that all Gentoo Linux users who are running
28 app-text/xpdf-1.01-r1 or earlier update their systems as
29 follows:
30
31 emerge rsync
32 emerge xpdf
33 emerge clean
34
35 - - --------------------------------------------------------------------
36 aliz@g.o - GnuPG key is available at www.gentoo.org/~aliz
37 - - --------------------------------------------------------------------
38 -----BEGIN PGP SIGNATURE-----
39 Version: GnuPG v1.2.1 (GNU/Linux)
40
41 iD8DBQE+FBHDfT7nyhUpoZMRArLLAJwJ/iqCxaKfUqvTSC6jXFTlwhA25ACfXosJ
42 CM9T0JTkOYDhJIVj7xgZ/5A=
43 =qDHF
44 -----END PGP SIGNATURE-----