Vulnerability Scanning Solutions, LLC.
Home
Our Process
Residential
Corporate
What We Scan For
Sample Report
Client List
Terms
Contact Us
What We Scan For
Family: Ubuntu Local Security Checks --> Category: infos

USN249-1 : xpdf, poppler, kdegraphics vulnerabilities Vulnerability Scan


Vulnerability Scan Summary
xpdf, poppler, kdegraphics vulnerabilities

Detailed Explanation for this Vulnerability Test

Synopsis :

These remote packages are missing security patches :
- kamera
- kcoloredit
- kdegraphics
- kdegraphics-dev
- kdegraphics-doc-html
- kdegraphics-kfile-tests
- kdvi
- kfax
- kgamma
- kghostview
- kiconedit
- kmrml
- kolourpaint
- kooka
- kpdf
- kpovmodeler
- kruler
- ksnapshot
- ksvg
- kuickshow
- kview
- kviewshell
- libkscan-dev
- libkscan1
- libpoppler-dev
- libpoppler-glib-dev
- libpoppler-qt-dev
- libpoppler0c2
- libpoppler0c2-glib
- libpoppler0c2-qt
- poppler-utils
- xp
[...]

Description :

The splash image handler in xpdf did not check the validity of
coordinates. By tricking a user into opening a specially crafted PDF
file, a possible hacker could exploit this to trigger a buffer overflow
which could lead to arbitrary code execution with the rights of
the user.

The poppler library and kpdf also contain xpdf code, and thus are
affected by the same vulnerability.

Solution :

Upgrade to :
- kamera-3.4.3-0ubuntu2.3 (Ubuntu 5.10)
- kcoloredit-3.4.3-0ubuntu2.3 (Ubuntu 5.10)
- kdegraphics-3.4.3-0ubuntu2.3 (Ubuntu 5.10)
- kdegraphics-dev-3.4.3-0ubuntu2.3 (Ubuntu 5.10)
- kdegraphics-doc-html-3.4.3-0ubuntu2.3 (Ubuntu 5.10)
- kdegraphics-kfile-tests-3.4.3-0ubuntu2.3 (Ubuntu 5.10)
- kdvi-3.4.3-0ubuntu2.3 (Ubuntu 5.10)
- kfax-3.4.3-0ubuntu2.3 (Ubuntu 5.10)
- kgamma-3.4.3-0ubuntu2.3 (Ubuntu 5.10)
- kghostview-3.4.3-0ubuntu2.3 (Ubuntu 5.10)
- kiconedit-3.4.3-0ubuntu2.3 (Ubuntu 5.10)
- k
[...]


Threat Level: High


Click HERE for more information and discussions on this network vulnerability scan.

VSS, LLC.

P.O. Box 827051

Pembroke Pines, FL 33082-7051

Vulnerability Scanning Solutions, LLC.