drucken bookmarks versenden konfigurieren admin pdf Sicherheit: Mehrere Probleme in PDFjam
Name: |
Mehrere Probleme in PDFjam |
|
ID: |
200903-05 |
|
Distribution: |
Gentoo |
|
Plattformen: |
Keine Angabe |
|
Datum: |
Sa, 7. März 2009, 17:30 |
|
Referenzen: |
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5743
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5843 |
|
Applikationen: |
PDFjam |
|
Originalnachricht |
--nextPart1553040.3KpQZE7hoI Content-Type: text/plain; charset="us-ascii" Content-Transfer-Encoding: 7bit Content-Disposition: inline
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200903-05 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - http://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Severity: Normal Title: PDFjam: Multiple vulnerabilities Date: March 07, 2009 Bugs: #252734 ID: 200903-05
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Synopsis ========
Multiple vulnerabilities in the PDFjam scripts allow for local privilege escalation.
Background ==========
PDFjam is a small collection of shell scripts to edit PDF documents, including pdfnup, pdfjoin and pdf90.
Affected packages =================
------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 app-text/pdfjam < 1.20-r1 >= 1.20-r1
Description ===========
* Martin Vaeth reported multiple untrusted search path vulnerabilities (CVE-2008-5843).
* Marcus Meissner of the SUSE Security Team reported that temporary files are created with a predictable name (CVE-2008-5743).
Impact ======
A local attacker could place a specially crafted Python module in the current working directory or the /var/tmp directory, and entice a user to run the PDFjam scripts, leading to the execution of arbitrary code with the privileges of the user running the application. A local attacker could also leverage symlink attacks to overwrite arbitrary files.
Workaround ==========
There is no known workaround at this time.
Resolution ==========
All PDFjam users should upgrade to the latest version:
# emerge --sync # emerge --ask --oneshot --verbose ">=app-text/pdfjam-1.20-r1"
References ==========
[ 1 ] CVE-2008-5843 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5843 [ 2 ] CVE-2008-5743 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5743
Availability ============
This GLSA and any updates to it are available for viewing at the Gentoo Security Website:
http://security.gentoo.org/glsa/glsa-200903-05.xml
Concerns? =========
Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users machines is of utmost importance to us. Any security concerns should be addressed to security@gentoo.org or alternatively, you may file a bug at http://bugs.gentoo.org.
License =======
Copyright 2009 Gentoo Foundation, Inc; referenced text belongs to its owner(s).
The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license.
http://creativecommons.org/licenses/by-sa/2.5
--nextPart1553040.3KpQZE7hoI Content-Type: application/pgp-signature; name=signature.asc Content-Description: This is a digitally signed message part.
-----BEGIN PGP SIGNATURE----- Version: GnuPG v2.0.9 (GNU/Linux)
iQIcBAABAgAGBQJJsp9eAAoJECaaHo/OfoM5BRYP/3wT+DXn1bWaSVf5L6dWSHeO uZ24+M0F4oZ51rR+cKPf9pi/+fAm71JyJc83WmmnjZNPx5I/PtCRnOdJxwx3DYl6 IOqu/otKrrziHF6axWGfUNPvzF3ABYrObxjQfeq1HcGiRGLYmn3E4DDs0HqzSvC+ C2i03nuxV3XR18j9sa+EahEPzDrjPZ2DT3S7mEMvjLVtv0JQnrzMJsdYbks6ARCu WhOxcvEcHriAxyu4jeIiSi/j2f3tLFK8LY5z+PfIeHHuq7HwJCYBOGj5rujkTN2d bpP7t2/C7XbfNojEmLyDAiS/qEe8CepiOvD5CNJZGLNkxsSUDEnrQ39uU3p9kwMs 1WLD0Ab/oizDRm4ZTzwIfAmHTAFnXXl/5Qa9FhX5Ijcz9rVO5+EXcua0lBTD9mfQ 8lQZdMqkWNM9H4ZDJKG0chlmzo3o2TdTAZ46otVb2XfMYwkXFXfxCMxTgSQsCKPC eFqOQu46vQohtWJbxi3UunE9jv+vb1DoS4SsOFDuCYyNcrPbdC1GEQnA8aRXq2Au ucuv3zdBwJk3X1ldvAyLn+gbxpRsqaXKR31UK6DJAegq/ygUjDKyQhrO9U7HeTVz Jt3sPIapRjdzxVBiJJtnM50wKRGHfkNDEzxvF1hQb39Y3xIQoz2HF7FqW+6TbMeb bVhcXOX5jTUOHV+f+OKq =oarB -----END PGP SIGNATURE-----
--nextPart1553040.3KpQZE7hoI--
|
|
|
|