Bug 171799 - media-gfx/inkscape < 0.45.1 format string vulnerability (CVE-2007-146{3|4})
|
Bug#:
171799
|
Product: Gentoo Security
|
Version: unspecified
|
Platform: All
|
|
OS/Version: Linux
|
Status: RESOLVED
|
Severity: normal
|
Priority: P2
|
|
Resolution: FIXED
|
Assigned To: security@gentoo.org
|
Reported By: py@gentoo.org
|
|
Component: Vulnerabilities
|
|
|
URL:
http://secunia.com/advisories/24615/
|
|
Summary: media-gfx/inkscape < 0.45.1 format string vulnerability (CVE-2007-146{3|4})
|
|
Keywords:
|
|
Status Whiteboard: B2 [glsa] p-y
|
|
Opened: 2007-03-22 14:02 0000
|
Some vulnerabilities have been reported in Inkscape, which
potentially can be exploited by malicious people to compromise a
user's system.
1) A format string error exists in certain dialogs. This can be
exploited to execute arbitrary code by tricking the user into opening
a specially crafted URI containing format string specifiers.
2) A format string error exists in the Whiteboard Jabber client,
which potentially can be exploited to execute arbitrary code.
Successful exploitation requires that the user is logged in to a
Jabber server.
The vulnerabilities are reported in versions prior to 0.45.1.
SOLUTION:
Update to version 0.45.1.
PROVIDED AND/OR DISCOVERED BY:
Kees Cook
graphics please advise and patch as necessary.
*** Bug 165715 has been marked as a duplicate of this bug. ***
(In reply to comment #1)
> graphics please advise and patch as necessary.
>
0.45.1 added to the tree. Arches please test and mark stable. Requires a newer
pstoedit stable too as users weren't able to import postscript files with
earlier versions:
betelgeuse@pena /usr/portage/media-gfx/inkscape $ adjutrix -w x86
=media-gfx/inkscape-0.45.1
Package Version Current Keywords Masks
============================= =================== ================= =========
media-gfx/pstoedit 3.44 ~x86
media-gfx/inkscape 0.45.1 ~x86
thanks arches, GLSA in progress...
GLSA 200704-10
thanks everyone
*** Bug 174815 has been marked as a duplicate of this bug. ***