Family: Fedora Local Security Checks --> Category: infos
Fedora Core 3 2005-727: netpbm Vulnerability Scan
Vulnerability Scan Summary
Check for the version of the netpbm package
Detailed Explanation for this Vulnerability Test
The remote host is missing the patch for the advisory FEDORA-2005-727 (netpbm).
The netpbm package contains a library of functions that support
programs for handling various graphics file formats, including .pbm
(portable bitmaps), .pgm (portable graymaps), .pnm (portable anymaps),
.ppm (portable pixmaps), and others.
pstopnm in netpbm does not properly use the '-dSAFER' option
when calling Ghostscript to convert a PostScript file into a
(1) PBM, (2) PGM, or (3) PNM file, which allows external
user-complicit attackers to execute arbitrary commands.
Solution : http://www.fedoranews.org/blog/index.php?p=847
Threat Level: High
Click HERE for more information and discussions on this network vulnerability scan.