Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.53304
Category:Debian Local Security Checks
Title:Debian Security Advisory DSA 222-1 (xpdf)
Summary:The remote host is missing an update to xpdf;announced via advisory DSA 222-1.
Description:Summary:
The remote host is missing an update to xpdf
announced via advisory DSA 222-1.

Vulnerability Insight:
iDEFENSE discovered an integer overflow in the pdftops filter from the
xpdf package that can be exploited to gain the privileges of the
target user. This can lead to gaining privileged access to the 'lp'
user if thee pdftops program is part of the print filter.

For the current stable distribution (woody) this problem has been
fixed in version 1.00-3.1.

For the old stable distribution (potato) this problem has been
fixed in version 0.90-8.1.

For the unstable distribution (sid) this problem has been
fixed in version 2.01-2.

Solution:
We recommend that you upgrade your xpdf package.

CVSS Score:
7.2

CVSS Vector:
AV:L/AC:L/Au:N/C:C/I:C/A:C

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2002-1384
BugTraq ID: 6475
http://www.securityfocus.com/bid/6475
Debian Security Information: DSA-222 (Google Search)
http://www.debian.org/security/2003/dsa-222
Debian Security Information: DSA-226 (Google Search)
http://www.debian.org/security/2003/dsa-226
Debian Security Information: DSA-232 (Google Search)
http://www.debian.org/security/2003/dsa-232
http://marc.info/?l=bugtraq&m=104152282309980&w=2
http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:001
http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:002
http://www.idefense.com/advisory/12.23.02.txt
http://www.redhat.com/support/errata/RHSA-2002-295.html
http://www.redhat.com/support/errata/RHSA-2002-307.html
http://www.redhat.com/support/errata/RHSA-2003-037.html
http://www.redhat.com/support/errata/RHSA-2003-216.html
SuSE Security Announcement: SUSE-SA:2003:002 (Google Search)
http://www.novell.com/linux/security/advisories/2003_002_cups.html
XForce ISS Database: pdftops-integer-overflow(10937)
https://exchange.xforce.ibmcloud.com/vulnerabilities/10937
CopyrightCopyright (C) 2008 E-Soft Inc.

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.