Debian DSA-222-1 : xpdf - integer overflow

high Nessus Plugin ID 15059

Synopsis

The remote Debian host is missing a security-related update.

Description

iDEFENSE discovered an integer overflow in the pdftops filter from the xpdf package that can be exploited to gain the privileges of the target user. This can lead to gaining unauthorized access to the 'lp' user if the pdftops program is part of the print filter.

Solution

Upgrade the xpdf package.

For the current stable distribution (woody) this problem has been fixed in version 1.00-3.1.

For the old stable distribution (potato) this problem has been fixed in version 0.90-8.1.

See Also

http://www.idefense.com/advisory/12.23.02.txt

http://www.debian.org/security/2003/dsa-222

Plugin Details

Severity: High

ID: 15059

File Name: debian_DSA-222.nasl

Version: 1.20

Type: local

Agent: unix

Published: 9/29/2004

Updated: 1/4/2021

Supported Sensors: Frictionless Assessment Agent, Nessus Agent, Agentless Assessment, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 6.7

CVSS v2

Risk Factor: High

Base Score: 7.2

Temporal Score: 6

Vector: CVSS2#AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Information

CPE: p-cpe:/a:debian:debian_linux:xpdf, cpe:/o:debian:debian_linux:2.2, cpe:/o:debian:debian_linux:3.0

Required KB Items: Host/local_checks_enabled, Host/Debian/release, Host/Debian/dpkg-l

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 1/6/2003

Reference Information

CVE: CVE-2002-1384

BID: 6475

DSA: 222