Nessus Plugin #16408

Plugin Index

Note: This file has been created from a downloaded version of the Nessus Plugins from http://www.nessus.org/. Therefore, the information here can be outdated.

[GLSA-200501-17] KPdf, KOffice: More vulnerabilities in included Xpdf

Family:
Gentoo Local Security Checks
Category:
infos
Copyright:
(C) 2005 Michel Arboi
Summary:
KPdf, KOffice: More vulnerabilities in included Xpdf
Version:
$Revision: 1.1 $
Cve_id:
CAN-2004-1125
Bugtraq_id:
-
Xrefs:
GLSA:200501-17
Description:
The remote host is affected by the vulnerability described in GLSA-200501-17
(KPdf, KOffice: More vulnerabilities in included Xpdf)


KPdf and KOffice both include Xpdf code to handle PDF files. Xpdf is
vulnerable to multiple new integer overflows, as described in GLSA
200412-24.

Impact

An attacker could entice a user to open a specially-crafted PDF file,
potentially resulting in the execution of arbitrary code with the
rights of the user running the affected utility.

Workaround

There is no known workaround at this time.

References:
http://www.gentoo.org/security/en/glsa/glsa-200412-24.xml
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2004-1125
http://kde.org/info/security/advisory-20041223-1.txt
http://koffice.kde.org/security/2004_xpdf_integer_overflow_2.php


Solution:
All KPdf users should upgrade to the latest version of kdegraphics:
# emerge --sync
# emerge --ask --oneshot --verbose kde-base/kdegraphics
All KOffice users should upgrade to the latest version:
# emerge --sync
# emerge --ask --oneshot --verbose app-office/koffice


Risk factor : Medium
Generiert am 27.04.2005 um 18:49:54 Uhr.