Summary
The remote host is missing updates announced in
advisory GLSA 200412-24.
Solution
All Xpdf users should upgrade to the latest version:
# emerge --sync
# emerge --ask --oneshot --verbose '>=app-text/xpdf-3.00-r7'
All GPdf users should also upgrade to the latest version:
# emerge --sync
# emerge --ask --oneshot --verbose '>=app-text/gpdf-2.8.1-r1'
http://www.securityspace.com/smysecure/catid.html?in=GLSA%20200412-24 http://bugs.gentoo.org/show_bug.cgi?id=75191
http://bugs.gentoo.org/show_bug.cgi?id=75201
http://www.idefense.com/application/poi/display?id=172&type=vulnerabilities&flashstatus=true
Insight
New integer overflows were discovered in Xpdf, potentially resulting in the execution of arbitrary code. GPdf includes Xpdf code and therefore is vulnerable to the same issues.
Severity
Classification
-
CVE CVE-2004-1125 -
CVSS Base Score: 9.3
AV:N/AC:M/Au:N/C:C/I:C/A:C
Related Vulnerabilities