- --------------------------------------------------------------------
GENTOO LINUX SECURITY ANNOUNCEMENT 200301-1
- --------------------------------------------------------------------

PACKAGE : xpdf
SUMMARY : integer overflow
DATE    : 2003-01-02 10:01 UTC
EXPLOIT : local and remote

- --------------------------------------------------------------------

From iDEFENSE advisory:

"The pdftops filter in the Xpdf and CUPS packages contains an integer
overflow that can be exploited to gain the privileges of the target user
or in some cases the increased privileges of the 'lp' user if installed
setuid. There are multiple ways of exploiting this vulnerability."

Read the full advisory at 
/us-en

SOLUTION

It is recommended that all Gentoo Linux users who are running
app-text/xpdf-1.01-r1 or earlier update their systems as
follows:

emerge rsync
emerge xpdf
emerge clean

- --------------------------------------------------------------------
aliz@gentoo.org - GnuPG key is available at - --------------------------------------------------------------------


Gentoo: xpdf buffer overflow vulnerability

The pdftops filter in the Xpdf and CUPS packages contains an integer overflow that can be exploited to gain the privileges of the target user or in some cases the increased privile...

Summary


- --------------------------------------------------------------------
GENTOO LINUX SECURITY ANNOUNCEMENT 200301-1
- --------------------------------------------------------------------
DATE    : 2003-01-02 10:01 UTC

- --------------------------------------------------------------------
From iDEFENSE advisory:
"The pdftops filter in the Xpdf and CUPS packages contains an integer overflow that can be exploited to gain the privileges of the target user or in some cases the increased privileges of the 'lp' user if installed setuid. There are multiple ways of exploiting this vulnerability."
Read the full advisory at /us-en
SOLUTION
It is recommended that all Gentoo Linux users who are running app-text/xpdf-1.01-r1 or earlier update their systems as follows:
emerge rsync emerge xpdf emerge clean
- -------------------------------------------------------------------- aliz@gentoo.org - GnuPG key is available at - --------------------------------------------------------------------

Resolution

References

Availability

Concerns

Severity
PACKAGE : xpdf
SUMMARY : integer overflow
EXPLOIT : local and remote

Synopsis

Background

Affected Packages

Impact

Workaround

Related News