First Last Prev Next    No search results available      Search page      Enter new bug
Bug#: 60205
Alias:
Product:
Component:
Status: RESOLVED
Resolution: FIXED
Assigned To: Gentoo Security <security@gentoo.org>
Hardware:
OS:
Version:
Priority:
Severity:
Reporter: bin-doph <bauer@dmsb.de>
Add CC:
CC:
Remove selected CCs
URL:
Summary:
Status Whiteboard:
Keywords:
Flags: Requestee:
 
 
  ()

Filename Description Type Creator Created Size Actions
Create a New Attachment (proposed patch, testcase, etc.) View All

Bug 60205 depends on: Show dependency tree
Bug 60205 blocks:

Additional Comments: (this is where you put emerge --info)


Not eligible to see or edit group visibility for this bug.






View Bug Activity   |   Format For Printing   |   XML   |   Clone This Bug


Description:   Opened: 2004-08-13 03:09 0000
Hi,

acroread seems vulnerable to this security-issue. The current version in portage (5.08) is not confirmed as vulnerable, but it says 

"While it is not clear exactly when the vulnerability was patched, iDEFENSE has tested Adobe Acrobat Reader (UNIX) 5.0.9, which appears to be patched against this vulnerability."

http://idefense.com/application/poi/display?id=125&type=vulnerabilities&flashstatus=true

------- Comment #1 From Tim Yamin (RETIRED) 2004-08-13 03:23:30 0000 -------
I've now marked 5.09 stable on x86, security team: please vote on a GLSA.

------- Comment #2 From Tim Yamin (RETIRED) 2004-08-13 03:33:58 0000 -------
The README has this to say:

==
New for Acrobat Reader 5.0.9

A security patch was applied that solves a couple of problems
reported with malformed uuencoded pdf files.
==

So < 5.09 should be vulnerable.

------- Comment #3 From Dominik Schäfer 2004-08-13 07:19:14 0000 -------
One of the bugs fixed in 5.09 seems to be this one: 
Shell Metacharacter Code Execution Vulnerability <http://idefense.com/application/poi/display?id=124&type=vulnerabilities>
Might be a good idea to include that vulnerability in the GLSA.

------- Comment #4 From Sune Kloppenborg Jeppesen 2004-08-14 00:57:49 0000 -------
I vote for a GLSA on this one and have drafted one already.

Security please review or vote nay to GLSA.

Thx Dominik

------- Comment #5 From Sune Kloppenborg Jeppesen 2004-08-15 07:58:52 0000 -------
GLSA 200408-14

First Last Prev Next    No search results available      Search page      Enter new bug