Summary
The remote host is missing updates announced in
advisory GLSA 200508-08.
Solution
All Xpdf users should upgrade to the latest version:
# emerge --sync
# emerge --ask --oneshot --verbose '>=app-text/xpdf-3.00-r10'
All GPdf users should upgrade to the latest version:
# emerge --sync
# emerge --ask --oneshot --verbose '>=app-text/gpdf-2.10.0-r1'
All Kpdf users should upgrade to the latest version:
# emerge --sync
# emerge --ask --oneshot --verbose '>=kde-base/kdegraphics-3.3.2-r3'
All KDE Split Ebuild Kpdf users should upgrade to the latest version:
# emerge --sync
# emerge --ask --oneshot --verbose '>=kde-base/kpdf-3.4.1-r1'
http://www.securityspace.com/smysecure/catid.html?in=GLSA%20200508-08 http://bugs.gentoo.org/show_bug.cgi?id=99769
http://bugs.gentoo.org/show_bug.cgi?id=100263
http://bugs.gentoo.org/show_bug.cgi?id=100265
Insight
Xpdf, Kpdf and GPdf may crash as a result of a Denial of Service vulnerability.
Severity
Classification
-
CVE CVE-2005-2097 -
CVSS Base Score: 2.1
AV:L/AC:L/Au:N/C:N/I:N/A:P
Related Vulnerabilities