Nessus Plugin #16408
Plugin Index
Note: This file has been created from a
downloaded version of the Nessus Plugins
from
http://www.nessus.org/.
Therefore, the information here can be outdated.
[GLSA-200501-17] KPdf, KOffice: More vulnerabilities in included Xpdf
- Family:
- Gentoo Local Security Checks
- Category:
- infos
- Copyright:
- (C) 2005 Michel Arboi
- Summary:
- KPdf, KOffice: More vulnerabilities in included Xpdf
- Version:
- $Revision: 1.1 $
- Cve_id:
- CAN-2004-1125
- Bugtraq_id:
- -
- Xrefs:
- GLSA:200501-17
- Description:
- The remote host is affected by the vulnerability described in GLSA-200501-17
(KPdf, KOffice: More vulnerabilities in included Xpdf)
KPdf and KOffice both include Xpdf code to handle PDF files. Xpdf is
vulnerable to multiple new integer overflows, as described in GLSA
200412-24.
Impact
An attacker could entice a user to open a specially-crafted PDF file,
potentially resulting in the execution of arbitrary code with the
rights of the user running the affected utility.
Workaround
There is no known workaround at this time.
References:
http://www.gentoo.org/security/en/glsa/glsa-200412-24.xml
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2004-1125
http://kde.org/info/security/advisory-20041223-1.txt
http://koffice.kde.org/security/2004_xpdf_integer_overflow_2.php
Solution:
All KPdf users should upgrade to the latest version of kdegraphics:
# emerge --sync
# emerge --ask --oneshot --verbose kde-base/kdegraphics
All KOffice users should upgrade to the latest version:
# emerge --sync
# emerge --ask --oneshot --verbose app-office/koffice
Risk factor : Medium
Generiert am 27.04.2005 um 18:49:54 Uhr.