GLSA-200710-20 : PDFKit, ImageKits: Buffer overflow

This script is Copyright (C) 2007-2015 Tenable Network Security, Inc.

Synopsis :

The remote Gentoo host is missing one or more security-related

Description :

The remote host is affected by the vulnerability described in GLSA-200710-20
(PDFKit, ImageKits: Buffer overflow)

Maurycy Prodeus discovered an integer overflow vulnerability possibly
leading to a stack-based buffer overflow in the XPDF code which PDFKit
is based on. ImageKits also contains a copy of PDFKit.

Impact :

By enticing a user to view a specially crafted PDF file with a viewer
based on ImageKits or PDFKit such as Gentoo's ViewPDF, a remote
attacker could cause an overflow, potentially resulting in the
execution of arbitrary code with the privileges of the user running the

Workaround :

There is no known workaround at this time.

See also :

Solution :

PDFKit and ImageKits are not maintained upstream, so the packages were
masked in Portage. We recommend that users unmerge PDFKit and
# emerge --unmerge gnustep-libs/pdfkit
# emerge --unmerge gnustep-libs/imagekits
As an alternative, users should upgrade their systems to use PopplerKit
instead of PDFKit and Vindaloo instead of ViewPDF.

Risk factor :

Medium / CVSS Base Score : 6.8
Public Exploit Available : true

Family: Gentoo Local Security Checks

Nessus Plugin ID: 27518 (gentoo_GLSA-200710-20.nasl)

Bugtraq ID:

CVE ID: CVE-2007-3387