|
Family: Gentoo Local Security Checks --> Category: infos
[GLSA-200501-17] KPdf, KOffice: More vulnerabilities in included Xpdf Vulnerability Scan
Vulnerability Scan Summary KPdf, KOffice: More vulnerabilities in included Xpdf
Detailed Explanation for this Vulnerability Test
The remote host is affected by the vulnerability described in GLSA-200501-17
(KPdf, KOffice: More vulnerabilities in included Xpdf)
KPdf and KOffice both include Xpdf code to handle PDF files. Xpdf is
vulnerable to multiple new integer overflows, as described in GLSA
200412-24.
Impact
A possible hacker could entice a user to open a specially-crafted PDF file,
potentially resulting in the execution of arbitrary code with the
rights of the user running the affected utility.
Workaround
There is no known workaround at this time.
References:
http://www.gentoo.org/security/en/glsa/glsa-200412-24.xml
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1125
http://kde.org/info/security/advisory-20041223-1.txt
http://koffice.kde.org/security/2004_xpdf_integer_overflow_2.php
Solution:
All KPdf users should upgrade to the latest version of kdegraphics:
# emerge --sync
# emerge --ask --oneshot --verbose kde-base/kdegraphics
All KOffice users should upgrade to the latest version:
# emerge --sync
# emerge --ask --oneshot --verbose app-office/koffice
Threat Level: Medium
Click HERE for more information and discussions on this network vulnerability scan.
|