Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 188861 - net-print/cups Vulnerabilities in included Xpdf code (CVE-2007-3387)
Summary: net-print/cups Vulnerabilities in included Xpdf code (CVE-2007-3387)
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High major
Assignee: Gentoo Security
URL: http://cve.mitre.org/cgi-bin/cvename....
Whiteboard: A2 [ebuild]
Keywords:
Depends on:
Blocks:
 
Reported: 2007-08-14 17:08 UTC by Sune Kloppenborg Jeppesen (RETIRED)
Modified: 2007-09-27 22:33 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2007-08-14 17:08:47 UTC
Integer overflow in the StreamPredictor::StreamPredictor function in gpdf before 2.8.2, as used in (1) poppler, (2) xpdf, (3) kpdf, (4) kdegraphics, (5) CUPS, and other products, might allow remote attackers to execute arbitrary code via a crafted PDF file.
Comment 1 Robert Buchholz (RETIRED) gentoo-dev 2007-09-08 02:29:02 UTC
printing, any updates here?

security, this has no whiteboard set.
Comment 2 Pierre-Yves Rofes (RETIRED) gentoo-dev 2007-09-08 07:49:44 UTC
printing, please provide fixed versions.
Comment 3 Stefan Schweizer (RETIRED) gentoo-dev 2007-09-08 09:17:24 UTC
what versions are affected? Are there already patches for versions where upstream has not yet released a new version?
Comment 4 Pierre-Yves Rofes (RETIRED) gentoo-dev 2007-09-08 10:02:55 UTC
The patch to apply is here:
ftp://ftp.foolabs.com/pub/xpdf/xpdf-3.02pl1.patch
It applies at least to cups in the pdftops dir with some minor changes (s/Stream.cc/Stream.cxx). I checked with the latest stable version (1.2.10-r1).
Mandriva also issued updates for some other packages : http://secunia.com/advisories/26425/
I don't see them in our tree, but I don't know how cups is packaged, maybe you'll want to check if everything is okay.
Comment 5 Robert Buchholz (RETIRED) gentoo-dev 2007-09-24 17:39:29 UTC
printing, please provide an updated version with the patch from
comment #4, otherwise security do a revbump of the current stable.
Comment 6 Stefan Schweizer (RETIRED) gentoo-dev 2007-09-27 22:33:00 UTC
188863 and 187139 fixed this.

cups and xpdf use poppler so the are fine.