Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 75199 - gnustep-libs/pdfkit is probably affected by new xpdf vuln
Summary: gnustep-libs/pdfkit is probably affected by new xpdf vuln
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All All
: High trivial (vote)
Assignee: Gentoo Security
URL:
Whiteboard: ~2 [noglsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2004-12-21 09:04 UTC by Thierry Carrez (RETIRED)
Modified: 2005-01-12 13:53 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Thierry Carrez (RETIRED) gentoo-dev 2004-12-21 09:04:35 UTC
pdfkit includes xpdf code and therefore might be vulnerable to CAN-2004-1125.
Please see bug 75191 for details and the patch.
Comment 1 Matthias Geerdsen (RETIRED) gentoo-dev 2004-12-21 12:07:19 UTC
PDFkit contains the vulnerable code
gnustep, pls provide an updated ebuild with the patches from bug 75191
Comment 2 Thierry Carrez (RETIRED) gentoo-dev 2004-12-28 12:40:07 UTC
*bump*
gnustep team: please patch and bump :)
Comment 3 Armando Di Cianno (RETIRED) gentoo-dev 2005-01-12 10:22:11 UTC
Not sure if I overlooked (noped, not in my mailbox) the previous emails -- was the gnustep@gentoo.org alias added recently?

Regardless, I'll get right on this; I'll likely contact the upstream maintainer too about this, as I think solely the last round of pdf vulnerabilities are officially known about by him, as posted on his website.

Comment 4 Thierry Carrez (RETIRED) gentoo-dev 2005-01-12 10:34:34 UTC
fafhrd: the gnustep Cc: was there at bug creation :)

Keep us posted !
Comment 5 Armando Di Cianno (RETIRED) gentoo-dev 2005-01-12 13:05:34 UTC
Patch applied; ebuild updated.

I leave the glory of closing the bug for the security team. ;-)
Comment 6 Thierry Carrez (RETIRED) gentoo-dev 2005-01-12 13:53:32 UTC
Thx fafhrd, closing.