Gentoo Forums
Gentoo Forums
Gentoo Forums
Quick Search: in
[ GLSA 200412-02 ] PDFlib: Multiple overflows in the included TIFF library
View unanswered posts
View posts from last 24 hours

 
Reply to topic    Gentoo Forums Forum Index News & Announcements
View previous topic :: View next topic  
Author Message
GLSA
Bodhisattva
Bodhisattva


Joined: 25 Feb 2003
Posts: 3826
Location: Essen, Germany

PostPosted: Sun Dec 05, 2004 5:47 pm    Post subject: [ GLSA 200412-02 ] PDFlib: Multiple overflows in the include Reply with quote

Gentoo Linux Security Advisory

Title: PDFlib: Multiple overflows in the included TIFF library (GLSA 200412-02)
Severity: normal
Exploitable: remote
Date: December 05, 2004
Bug(s): #69043
ID: 200412-02

Synopsis

PDFlib is vulnerable to multiple overflows, which can potentially lead to the execution of arbitrary code.

Background

PDFlib is a library providing functions to handle PDF files. It includes a modified TIFF library used to process TIFF images.

Affected Packages

Package: media-libs/pdflib
Vulnerable: < 5.0.4_p1
Unaffected: >= 5.0.4_p1
Architectures: All supported architectures


Description

The TIFF library is subject to several known vulnerabilities (see GLSA 200410-11). Most of these overflows also apply to PDFlib.

Impact

A remote attacker could entice a user or web application to process a carefully crafted PDF file or TIFF image using a PDFlib-powered program. This can potentially lead to the execution of arbitrary code with the rights of the program processing the file.

Workaround

There is no known workaround at this time.

Resolution

All PDFlib users should upgrade to the latest version:
Code:
# emerge --sync
# emerge --ask --oneshot --verbose ">=media-libs/pdflib-5.0.4_p1"


References

PDFlib ChangeLog
CAN-2004-0803
CAN-2004-0804
CAN-2004-0886
GLSA 200410-11


Last edited by GLSA on Thu Aug 10, 2006 4:16 am; edited 3 times in total
Back to top
View user's profile Send private message
Display posts from previous:   
Reply to topic    Gentoo Forums Forum Index News & Announcements All times are GMT
Page 1 of 1

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum