- - - ---------------------------------------------------------------------
GENTOO LINUX SECURITY ANNOUNCEMENT 200306-11
- - - ---------------------------------------------------------------------

          PACKAGE : xpdf
          SUMMARY : arbitrary code execution
             DATE : 2003-06-25 21:48 UTC
          EXPLOIT : remote
VERSIONS AFFECTED : =xpdf-2.02.1
              CVE : CAN-2003-0434

- - - ---------------------------------------------------------------------

from advisory: 
"Valid PDF files can contain malicious external-type hyperlinks that can 
execute arbitrary shell commands underneath Unix with various PDF 
viewers/readers.

The hyperlinks must be activated or followed for the malicious script 
to run.  The obvious case is for a user to click on one. "

Read the full advisory at 
http://marc.theaimsgroup.com/?l=full-disclosure&m=105555332025253&w=2

SOLUTION

It is recommended that all Gentoo Linux users who are running
app-text/xpdf upgrade to xpdf-2.02.1 as follows

emerge sync
emerge xpdf
emerge clean

- - - ---------------------------------------------------------------------
aliz@gentoo.org - GnuPG key is available at   
- - - ---------------------------------------------------------------------

Gentoo: xpdf arbitrary code execution vulnerability

Valid PDF files can contain malicious external-type hyperlinks that can execute arbitrary shell commands underneath Unix with various PDF viewers/readers.

Summary


GENTOO LINUX SECURITY ANNOUNCEMENT 200306-11


from advisory: "Valid PDF files can contain malicious external-type hyperlinks that can execute arbitrary shell commands underneath Unix with various PDF viewers/readers.
The hyperlinks must be activated or followed for the malicious script to run. The obvious case is for a user to click on one. "
Read the full advisory at http://marc.theaimsgroup.com/?l=full-disclosure&m=105555332025253&w=2
SOLUTION
It is recommended that all Gentoo Linux users who are running app-text/xpdf upgrade to xpdf-2.02.1 as follows
emerge sync emerge xpdf emerge clean
aliz@gentoo.org - GnuPG key is available at

Resolution

References

Availability

Concerns

Severity
PACKAGE : xpdf
SUMMARY : arbitrary code execution
DATE : 2003-06-25 21:48 UTC
EXPLOIT : remote
VERSIONS AFFECTED : =xpdf-2.02.1
CVE : CAN-2003-0434

Synopsis

Background

Affected Packages

Impact

Workaround

Related News