Alerts This Week
Warning Icon 1 631
Alerts This Week
Warning Icon 1 631

Debian: 202307-2 Critical: Evince Memory Corruption Vulnerability

gentoo
Calendar Grey January 2, 2003
Dist Gentoo Esm H88
Stay informed about the latest Gentoo security advisory related to xpdf, detailing an integer overflow vulnerability along with information on how it could be exploited.
The pdftops filter in the Xpdf and CUPS packages contains an integer overflow that can be exploited to gain the privileges of the target user or in some cases the increased privile...

Summary


- --------------------------------------------------------------------
GENTOO LINUX SECURITY ANNOUNCEMENT 200301-1
- --------------------------------------------------------------------
DATE    : 2003-01-02 10:01 UTC

- --------------------------------------------------------------------
From iDEFENSE advisory:
"The pdftops filter in the Xpdf and CUPS packages contains an integer overflow that can be exploited to gain the privileges of the target user or in some cases the increased privileges of the 'lp' user if installed setuid. There are multiple ways of exploiting this vulnerability."
Read the full advisory at /us-en
SOLUTION
It is recommended that all Gentoo Linux users who are running app-text/xpdf-1.01-r1 or earlier update their systems as follows:
emerge rsync emerge xpdf emerge clean
- -------------------------------------------------------------------- aliz@gentoo.org - GnuPG key is available at - --------------------------------------------------------------------

Resolution

References

Availability

style>.gentoo_availability{display:block;}

Concerns

Severity
critical
Lowest
Low
Medium
High
Critical

PACKAGE : xpdf
SUMMARY : integer overflow
EXPLOIT : local and remote

Synopsis

Background

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Affected Packages

Impact

Workaround

Related News

Your message here