Gentoo Linux Multiple PDF EBuild Updates Unspecified Vulnerability
BID:11614
Info
Gentoo Linux Multiple PDF EBuild Updates Unspecified Vulnerability
| Bugtraq ID: | 11614 |
| Class: | Unknown |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 06 2004 12:00AM |
| Updated: | Nov 06 2004 12:00AM |
| Credit: | This vulnerability was announced by the vendor. |
| Vulnerable: |
Gentoo Linux |
| Not Vulnerable: | |
Discussion
Gentoo Linux Multiple PDF EBuild Updates Unspecified Vulnerability
Gentoo Linux released updated Xpdf, CUPS, GPdf, KPDF and KOffice eBuilds to address the vulnerability described in BID 11501 (Xpdf PDFTOPS Multiple Integer Overflow Vulnerabilities) on October 28, 2004.
The vendor has reported that these updated eBuilds introduced an unspecified vulnerability. The vulnerability is reported to present itself only on 64-bit platforms.
Gentoo Linux released updated Xpdf, CUPS, GPdf, KPDF and KOffice eBuilds to address the vulnerability described in BID 11501 (Xpdf PDFTOPS Multiple Integer Overflow Vulnerabilities) on October 28, 2004.
The vendor has reported that these updated eBuilds introduced an unspecified vulnerability. The vulnerability is reported to present itself only on 64-bit platforms.
Exploit / POC
Gentoo Linux Multiple PDF EBuild Updates Unspecified Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Gentoo Linux Multiple PDF EBuild Updates Unspecified Vulnerability
Solution:
Gentoo Linux originally released advisory GLSA 200410-20 and GLSA 200410-30 to address BID 11501 (Xpdf PDFTOPS Multiple Integer Overflow Vulnerabilities). The vendor later reported that the eBuilds released with these advisories introduced an unspecified vulnerability on 64-bit platforms. The vendor has released advisories GLSA 200410-20:02, GLSA 200410-30:02, and updated eBuilds to address this issue. These updated eBuilds can be applied as follows:
To address the issues in Xpdf as well as CUPS. Users of affected packages are urged to execute the following commands with superuser privileges:
Xpdf users:
emerge --sync
emerge --ask --oneshot --verbose ">=app-text/xpdf-3.00-r5"
CUPS users:
emerge --sync
emerge --ask --oneshot --verbose ">=net-print/cups-1.1.20-r5"
To address the issues in GPdf, KPDF and KOffice. Users of affected packages are urged to execute the following commands to upgrade their computers:
GPdf users:
emerge --sync
emerge --ask --oneshot --verbose ">=app-text/gpdf-0.132-r2"
KDE users:
emerge --sync
emerge --ask --oneshot --verbose ">=kde-base/kdegraphics-3.3.0-r2"
KOffice users:
emerge --sync
emerge --ask --oneshot --verbose ">=app-office/koffice-1.3.3-r2"
Please see the referenced advisories for further information.
Solution:
Gentoo Linux originally released advisory GLSA 200410-20 and GLSA 200410-30 to address BID 11501 (Xpdf PDFTOPS Multiple Integer Overflow Vulnerabilities). The vendor later reported that the eBuilds released with these advisories introduced an unspecified vulnerability on 64-bit platforms. The vendor has released advisories GLSA 200410-20:02, GLSA 200410-30:02, and updated eBuilds to address this issue. These updated eBuilds can be applied as follows:
To address the issues in Xpdf as well as CUPS. Users of affected packages are urged to execute the following commands with superuser privileges:
Xpdf users:
emerge --sync
emerge --ask --oneshot --verbose ">=app-text/xpdf-3.00-r5"
CUPS users:
emerge --sync
emerge --ask --oneshot --verbose ">=net-print/cups-1.1.20-r5"
To address the issues in GPdf, KPDF and KOffice. Users of affected packages are urged to execute the following commands to upgrade their computers:
GPdf users:
emerge --sync
emerge --ask --oneshot --verbose ">=app-text/gpdf-0.132-r2"
KDE users:
emerge --sync
emerge --ask --oneshot --verbose ">=kde-base/kdegraphics-3.3.0-r2"
KOffice users:
emerge --sync
emerge --ask --oneshot --verbose ">=app-office/koffice-1.3.3-r2"
Please see the referenced advisories for further information.
References
Gentoo Linux Multiple PDF EBuild Updates Unspecified Vulnerability
References:
References: