-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - - -------------------------------------------------------------------- GENTOO LINUX SECURITY ANNOUNCEMENT 200301-1 - - -------------------------------------------------------------------- PACKAGE : xpdf SUMMARY : integer overflow DATE : 2003-01-02 10:01 UTC EXPLOIT : local and remote - - -------------------------------------------------------------------- - From iDEFENSE advisory: "The pdftops filter in the Xpdf and CUPS packages contains an integer overflow that can be exploited to gain the privileges of the target user or in some cases the increased privileges of the 'lp' user if installed setuid. There are multiple ways of exploiting this vulnerability." Read the full advisory at http://www.idefense.com/advisory/12.23.02.txt SOLUTION It is recommended that all Gentoo Linux users who are running app-text/xpdf-1.01-r1 or earlier update their systems as follows: emerge rsync emerge xpdf emerge clean - - -------------------------------------------------------------------- aliz@gentoo.org - GnuPG key is available at www.gentoo.org/~aliz - - -------------------------------------------------------------------- -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.2.1 (GNU/Linux) iD8DBQE+FBHDfT7nyhUpoZMRArLLAJwJ/iqCxaKfUqvTSC6jXFTlwhA25ACfXosJ CM9T0JTkOYDhJIVj7xgZ/5A= =qDHF -----END PGP SIGNATURE-----