Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 515
Alerts This Week
Warning Icon 1 515

Gentoo: GLSA-200411-30 Normal: pdftohtml Code Execution Risk

gentoo
Calendar Grey November 23, 2004
Scroller Gentoo
To boost Gentoo Linux security, update pdftohtml for vulnerability fixes that may permit malicious PDF code execution. Sync repositories and upgrade pdftohtml for security
pdftohtml includes vulnerable Xpdf code to handle PDF files, making it vulnerable to execution of arbitrary code upon converting a malicious PDF file

Summary

Gentoo Linux Security Advisory GLSA 200411-30 https://security.gentoo.org/ Severity: Normal Title: pdftohtml: Vulnerabilities in included Xpdf Date: November 23, 2004 Bugs: #69019 ID: 200411-30

Synopsis ======= pdftohtml includes vulnerable Xpdf code to handle PDF files, making it vulnerable to execution of arbitrary code upon converting a malicious PDF file.
Background ========= pdftohtml is a utility to convert PDF files to HTML or XML formats. It makes use of Xpdf code to decode PDF files.
Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 app-text/pdftohtml <= 0.36 >= 0.36-r1
========== Xpdf is vulnerable to multiple integer overflows, as described in GLSA 200410-20.
Impact ===== An att...

Read the Full Advisory

Resolution

References

Availability

style>.gentoo_availability{display:block;}

Concerns

Synopsis

Background

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Affected Packages

Impact

Workaround