GLSA Bodhisattva
Joined: 25 Feb 2003 Posts: 3829 Location: Essen, Germany
|
Posted: Tue Jan 11, 2005 1:43 pm Post subject: [ GLSA 200501-17 ] KPdf, KOffice: More vulnerabilities in in |
|
|
Gentoo Linux Security Advisory
Title: KPdf, KOffice: More vulnerabilities in included Xpdf (GLSA 200501-17)
Severity: normal
Exploitable: remote
Date: January 11, 2005
Updated: January 12, 2005
Bug(s): #75203, #75204
ID: 200501-17
Synopsis
KPdf and KOffice both include vulnerable Xpdf code to handle PDF files,
making them vulnerable to the execution of arbitrary code if a user is
enticed to view a malicious PDF file.
Background
KPdf is a KDE-based PDF viewer included in the kdegraphics package.
KOffice is an integrated office suite for KDE.
Affected Packages
Package: app-office/koffice
Vulnerable: < 1.3.5-r1
Unaffected: >= 1.3.5-r1
Architectures: All supported architectures
Package: kde-base/kdegraphics
Vulnerable: < 3.3.2-r1
Unaffected: >= 3.3.2-r1
Unaffected: >= 3.2.3-r3 < 3.2.4
Architectures: All supported architectures
Description
KPdf and KOffice both include Xpdf code to handle PDF files. Xpdf is
vulnerable to multiple new integer overflows, as described in GLSA
200412-24.
Impact
An attacker could entice a user to open a specially-crafted PDF file,
potentially resulting in the execution of arbitrary code with the
rights of the user running the affected utility.
Workaround
There is no known workaround at this time.
Resolution
All KPdf users should upgrade to the latest version of kdegraphics:
Code: | # emerge --sync
# emerge --ask --oneshot --verbose kde-base/kdegraphics |
All KOffice users should upgrade to the latest version:
Code: | # emerge --sync
# emerge --ask --oneshot --verbose app-office/koffice |
References
GLSA 200412-24
CAN-2004-1125
KDE Security Advisory: kpdf Buffer Overflow Vulnerability
KOffice XPDF Integer Overflow 2
Last edited by GLSA on Mon Jun 10, 2013 4:18 am; edited 2 times in total |
|