GLSA Advocate

Joined: 12 May 2004 Posts: 2663
|
Posted: Thu Aug 18, 2005 9:47 am Post subject: [ GLSA 200508-08 ] Xpdf, Kpdf, GPdf: Denial of Service vulne |
|
|
Gentoo Linux Security Advisory
Title: Xpdf, Kpdf, GPdf: Denial of Service vulnerability (GLSA 200508-08)
Severity: normal
Exploitable: remote
Date: August 16, 2005
Bug(s): #99769, #100263, #100265
ID: 200508-08
Synopsis
Xpdf, Kpdf and GPdf may crash as a result of a Denial of Service vulnerability.
Background
Xpdf, Kpdf and GPdf are PDF file viewers that run under the X Window System. Kpdf and GPdf both contain Xpdf code. Kpdf is also part of kdegraphics.
Affected Packages
Package: app-text/xpdf
Vulnerable: < 3.00-r10
Unaffected: >= 3.00-r10
Architectures: All supported architectures
Package: kde-base/kdegraphics
Vulnerable: < 3.3.2-r3
Unaffected: >= 3.3.2-r3
Architectures: All supported architectures
Package: kde-base/kpdf
Vulnerable: < 3.4.1-r1
Unaffected: >= 3.4.1-r1
Architectures: All supported architectures
Package: app-text/gpdf
Vulnerable: < 2.10.0-r1
Unaffected: >= 2.10.0-r1
Architectures: All supported architectures
Description
Xpdf, Kpdf and GPdf do not handle a broken table of embedded TrueType fonts correctly. After detecting such a table, Xpdf, Kpdf and GPdf attempt to reconstruct the information in it by decoding the PDF file, which causes the generation of a huge temporary file.
Impact
A remote attacker may cause a Denial of Service by creating a specially crafted PDF file, sending it to a CUPS printing system (which uses Xpdf), or by enticing a user to open it in Xpdf, Kpdf, or GPdf.
Workaround
There is no known workaround at this time.
Resolution
All Xpdf users should upgrade to the latest version: Code: | # emerge --sync
# emerge --ask --oneshot --verbose ">=app-text/xpdf-3.00-r10" | All GPdf users should upgrade to the latest version: Code: | # emerge --sync
# emerge --ask --oneshot --verbose ">=app-text/gpdf-2.10.0-r1" | All Kpdf users should upgrade to the latest version: Code: | # emerge --sync
# emerge --ask --oneshot --verbose ">=kde-base/kdegraphics-3.3.2-r3" | All KDE Split Ebuild Kpdf users should upgrade to the latest version: Code: | # emerge --sync
# emerge --ask --oneshot --verbose ">=kde-base/kpdf-3.4.1-r1" |
References
CAN-2005-2097
Last edited by GLSA on Sun May 07, 2006 4:58 pm; edited 1 time in total |
|