Important: tetex security update. Date: Tue, 13 Nov 2007 17:03:33 -0600 Reply-To: Troy Dawson Sender: Security Errata for Scientific Linux From: Troy Dawson Subject: Security ERRATA for tetex on SL5.x, SL4.x, SL3,x i386/x86_64 Comments: To:
KPdf includes vulnerable Xpdf code to handle PDF files, making it vulnerable to the execution of arbitrary code.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200602-05 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: KPdf: Heap based overflow Date: February 12, 2006 Bugs: #121375 ID: 200602-05 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= KPdf includes vulnerable Xpdf code to handle PDF files, making it vulnerable to the execution of arbitrary code. Background ========= KPdf is a KDE-based PDF viewer included in the kdegraphics package. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 kde-base/kdegraphics < 3.4.3-r4 > = 3.4.3-r4 2 kde-base/kpdf < 3.4.3-r4 > = 3.4.3-r4 ------------------------------------------------------------------- 2 affected packages on all of their supported architectures. ------------------------------------------------------------------- Description ========== KPdf includes Xpdf code to handle PDF files. Dirk Mueller discovered that the Xpdf code is vulnerable a heap based overflow in the splash rasterizer engine. Impact ===== An attacker could entice a user to open a specially crafted PDF file with Kpdf, potentially resulting in the execution of arbitrary code with the rights of the user running the affected application. Workaround ========= There is no known workaround at this time. Resolution ========= All kdegraphics users should upgrade to the latestversion: # emerge --sync # emerge --ask --oneshot --verbose "> =kde-base/kdegraphics-3.4.3-r4" All Kpdf users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =kde-base/kpdf-3.4.3-r4" References ========= [ 1 ] CVE-2006-0301 https://www.cve.org/CVERecord?id=CVE-2006-0301 [ 2 ] KDE Security Advisory: kpdf/xpdf heap based buffer overflow https://kde.org/info/security/advisory-20060202-1.txt Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/200602-05 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users machines is of utmost importance to us. Any security concerns should be addressed to
Get the latest Linux and open source security news straight to your inbox.