LWN.net Logo

xpdf: integer overflow

Package(s):xpdf CVE #(s):CAN-2002-1384
Created:January 2, 2003 Updated:February 6, 2003
Description: - From iDEFENSE advisory:
The pdftops filter in the Xpdf and CUPS packages contains an integer overflow that can be exploited to gain the privileges of the target user or in some cases the increased privileges of the 'lp' user if installed setuid. There are multiple ways of exploiting this vulnerability.

Read the full advisory at http://www.idefense.com/advisory/12.23.02.txt

Alerts:
Red Hat RHSA-2003:037-09 2003-02-06
Debian DSA-226-1 2003-01-10
Mandrake MDKSA-2003:002 2003-01-09
Debian DSA-222-1 2003-01-06
Gentoo 200301-1 2003-01-02

(Log in to post comments)

Copyright © 2012, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds